## This update fixes the following issues: grafana was updated from version 11.5.7 to 11.5.10: * Security issues fixed: * CVE-2025-64751: Drop experimental implementation of authorization Zanzana server/client (version 11.5.10) (bsc#1254113) * CVE-2025-47911: Fix parsing HTML documents (version 11.5.10) (bsc#1251454) * CVE-2025-58190: Fix excessive memory consumption (version 11.5.10) (bsc#1251657) * CVE-2025-11065: Fixed sensitive information leak in logs (version 11.5.9) (bsc#1250616) * Other changes, new features and bugs fixed: * Version 11.5.10: * Use forked wire from Grafana repository instead of external package (jsc#PED-14178) * Auth: Fix render user OAuth passthrough. * LDAP Authentication: Fix URL to propagate username context as parameter.
* bsc#1249434
* bsc#1250616
* bsc#1251454
* bsc#1251657
* bsc#1254113
* jsc#MSQA-1038
* jsc#PED-14178
Cross-
* CVE-2025-11065
* CVE-2025-47911
* CVE-2025-58190
* CVE-2025-64751
CVSS scores:
* CVE-2025-11065 ( SUSE ): 5.7
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2025-11065 ( SUSE ): 4.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
* CVE-2025-47911 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2025-47911 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2025-58190 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2025-58190 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2025-64751 ( SUSE ): 5.3
Get the latest Linux and open source security news straight to your inbox.