Alerts This Week
Warning Icon 1 1,213
Alerts This Week
Warning Icon 1 1,213

openSUSE: Security Update 2025:0545-1 for Grafana Released

opensuse
Calendar Grey February 14, 2025
Dist Opensuse Esm H88
This bulletin details the software patch for Grafana on openSUSE, focusing on a number of moderate vulnerabilities.
An update that solves five vulnerabilities and contains three features can now be installed.

Description

This update for grafana fixes the following issues:

grafana was updated from version 9.5.18 to 10.4.13

(jsc#PED-11591,jsc#PED-11649):

* Security issues fixed:

* CVE-2024-45337: Prevent possible misuse of ServerConfig.PublicKeyCallback by

upgrading golang.org/x/crypto (bsc#1234554)

* CVE-2023-3128: Fixed authentication bypass using Azure AD OAuth

(bsc#1212641)

* CVE-2023-6152: Add email verification when updating user email (bsc#1219912)

* CVE-2024-6837: Fixed potential data source permission escalation

(bsc#1236301)

* CVE-2024-8118: Fixed permission on external alerting rule write endpoint

(bsc#1231024)

* Potential breaking changes in version 10:

* In panels using the `extract fields` transformation, where one of the

extracted names collides with one of the already existing ields, the

extracted field will be renamed.

* For the existing backend mode users who have table visualization might see

some inconsistencies on their panels. We...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.6

zypper in -t patch openSUSE-SLE-15.6-2025-545=1

* SUSE Package Hub 15 15-SP6

zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-545=1

Package List

* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)

* grafana-10.4.13-150200.3.59.1

* grafana-debuginfo-10.4.13-150200.3.59.1

* SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64)

* grafana-10.4.13-150200.3.59.1

* grafana-debuginfo-10.4.13-150200.3.59.1

References

* bsc#1212641

* bsc#1219912

* bsc#1231024

* bsc#1234554

* bsc#1236301

* jsc#MSQA-914

* jsc#PED-11591

* jsc#PED-11649

## References:

* https://www.suse.com/security/cve/CVE-2023-3128.html

* https://www.suse.com/security/cve/CVE-2023-6152.html

* https://www.suse.com/security/cve/CVE-2024-45337.html

* https://www.suse.com/security/cve/CVE-2024-6837.html

* https://www.suse.com/security/cve/CVE-2024-8118.html

* https://bugzilla.suse.com/show_bug.cgi?id=1212641

* https://bugzilla.suse.com/show_bug.cgi?id=1219912

* https://bugzilla.suse.com/show_bug.cgi?id=1231024

* https://bugzilla.suse.com/show_bug.cgi?id=1234554

* https://bugzilla.suse.com/show_bug.cgi?id=1236301

* https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FMSQA-914&page_caps=&user_role=

* https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-11591&page_caps=&user_role=

* https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-11649&page_caps=&user_role=

Announcement ID: SUSE-SU-2025:0545-1
Release Date: 2025-02-14T07:24:23Z
Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here