-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: grafana security, bug fix, and enhancement update
Advisory ID:       RHSA-2021:1859-01
Product:           Red Hat Enterprise Linux
Advisory URL:      https://access.redhat.com/errata/RHSA-2021:1859
Issue date:        2021-05-18
CVE Names:         CVE-2020-24303 CVE-2020-27846 
====================================================================
1. Summary:

An update for grafana is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64

3. Description:

Grafana is an open source, feature rich metrics dashboard and graph editor
for Graphite, InfluxDB & OpenTSDB. 

The following packages have been upgraded to a later upstream version:
grafana (7.3.6). (BZ#1850471)

Security Fix(es):

* crewjam/saml: authentication bypass in saml authentication
(CVE-2020-27846)

* grafana: XSS via a query alias for the Elasticsearch and Testdata
datasource (CVE-2020-24303)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.4 Release Notes linked from the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1843170 - grafana may not start due to permission issues
1850471 - Rebase of Grafana to version 7+
1892418 - CVE-2020-24303 grafana: XSS via a query alias for the Elasticsearch and Testdata datasource
1907670 - CVE-2020-27846 crewjam/saml: authentication bypass in saml authentication
1916083 - grafana-cli crashes when run from root's home directory

6. Package List:

Red Hat Enterprise Linux AppStream (v. 8):

Source:
grafana-7.3.6-2.el8.src.rpm

aarch64:
grafana-7.3.6-2.el8.aarch64.rpm
grafana-debuginfo-7.3.6-2.el8.aarch64.rpm

ppc64le:
grafana-7.3.6-2.el8.ppc64le.rpm
grafana-debuginfo-7.3.6-2.el8.ppc64le.rpm

s390x:
grafana-7.3.6-2.el8.s390x.rpm
grafana-debuginfo-7.3.6-2.el8.s390x.rpm

x86_64:
grafana-7.3.6-2.el8.x86_64.rpm
grafana-debuginfo-7.3.6-2.el8.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2020-24303
https://access.redhat.com/security/cve/CVE-2020-27846
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.4_release_notes/

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYKPvytzjgjWX9erEAQj5FBAAhESRJBBFxnxUi3BwEY1kV+nLlIPxvIOY
1JYaUyhrnC6aefns5zDKGt8xJxQi/u1k0/ibiY4XWVy1WWuDtcp370b4IHMbuVD5
IcDkngTcrdkNfqrEyXsLVNO4/UMn65U6yfXs4RCZgg+l4OUgdoC1kxL0XPEsfvc7
JegRhK9QKWqXUcw/26ordsyuOPwd5ok7ndoP0BusJaC6qv/QOeP3ebIckcD9vLdj
bOHXYQs9p2Of37z/yJq2gG1FybRUnxlB34aoyMsJUmKcAL2LMDoIVSkPygz+VDBN
+e+/un2WvS7d/CIBxJo8ncIvzg87aGjgwyjBM+5cLExPQOk8JJuTvYNWdExHEuqY
cwayYv9wtGKwseEVlycndYie8myVBXdgGH0hL784SiDt5uxJyTv5d6KTJ71+Fmit
e+OI/YEEAzs3AAvO7M1IboGicg5M7j0HvsKDaWML1b+Y9IOszrk33SFDxg0x25Dd
q3nRQ2mGBWsWVllwlnKBgAGgrsU3m/rVmtQUC98YuvmQYRWO3XRL629KlhuwEcSC
S9CPRaHpok/A/M/i7qgtypJp0SeolNdAT1HdWq6CMGY3ZnUUpS3mMq+HkRm1PfC6
Ooxn/xE4rq71XMYft1akAbtUdRbKuFWopA5U9+uaVvWx8X6HPRXC15JknmgAD8Rd
RMgcQD8B7A8=2xAS
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2021-1859:01 Moderate: grafana security, bug fix,

An update for grafana is now available for Red Hat Enterprise Linux 8

Summary

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.
The following packages have been upgraded to a later upstream version: grafana (7.3.6). (BZ#1850471)
Security Fix(es):
* crewjam/saml: authentication bypass in saml authentication (CVE-2020-27846)
* grafana: XSS via a query alias for the Elasticsearch and Testdata datasource (CVE-2020-24303)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.4 Release Notes linked from the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2020-24303 https://access.redhat.com/security/cve/CVE-2020-27846 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.4_release_notes/

Package List

Red Hat Enterprise Linux AppStream (v. 8):
Source: grafana-7.3.6-2.el8.src.rpm
aarch64: grafana-7.3.6-2.el8.aarch64.rpm grafana-debuginfo-7.3.6-2.el8.aarch64.rpm
ppc64le: grafana-7.3.6-2.el8.ppc64le.rpm grafana-debuginfo-7.3.6-2.el8.ppc64le.rpm
s390x: grafana-7.3.6-2.el8.s390x.rpm grafana-debuginfo-7.3.6-2.el8.s390x.rpm
x86_64: grafana-7.3.6-2.el8.x86_64.rpm grafana-debuginfo-7.3.6-2.el8.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2021:1859-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2021:1859
Issued Date: : 2021-05-18
CVE Names: CVE-2020-24303 CVE-2020-27846

Topic

An update for grafana is now available for Red Hat Enterprise Linux 8.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64


Bugs Fixed

1843170 - grafana may not start due to permission issues

1850471 - Rebase of Grafana to version 7+

1892418 - CVE-2020-24303 grafana: XSS via a query alias for the Elasticsearch and Testdata datasource

1907670 - CVE-2020-27846 crewjam/saml: authentication bypass in saml authentication

1916083 - grafana-cli crashes when run from root's home directory


Related News