Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2022:3676-1 Critical: Grafana XSS and Privilege Escalation Fix

suse
Calendar Grey October 20, 2022
Dist Suse Esm H88
Resolves 14 vulnerabilities, such as severe XSS and privilege escalation in Grafana. Update recommended for SUSE clientele.
An update that fixes 14 vulnerabilities, contains four features is now available

Summary

This update for grafana fixes the following issues: Updated to version 8.5.13 (jsc#PED-2145, jsc#SLE-23439, jsc#SLE-23422, jsc#SLE-24565): - CVE-2022-36062: Fixed RBAC folders/dashboards privilege escalation (bsc#1203596). - CVE-2022-35957: Fixed escalation from admin to server admin when auth proxy is used (bsc#1203597). - CVE-2022-31107: Fixed OAuth account takeover (bsc#1201539). - CVE-2022-31097: Fixed XSS vulnerability in the Unified Alerting (bsc#1201535). - CVE-2022-21702: Fixed XSS vulnerability in handling data sources (bsc#1195726). - CVE-2022-21703: Fixed cross-origin request forgery vulnerability (bsc#1195727). - CVE-2022-21713: Fixed Insecure Direct Object Reference vulnerability in Teams API (bsc#1195728).

References

#1188571 #1189520 #1192383 #1192763 #1193492

#1193686 #1194873 #1195726 #1195727 #1195728

#1201535 #1201539 #1203596 #1203597 PED-2145

SLE-23422 SLE-23439 SLE-24565

Cross- CVE-2021-36222 CVE-2021-3711 CVE-2021-41174

CVE-2021-41244 CVE-2021-43798 CVE-2021-43815

CVE-2022-21673 CVE-2022-21702 CVE-2022-21703

CVE-2022-21713 CVE-2022-31097 CVE-2022-31107

CVE-2022-35957 CVE-2022-36062

CVSS scores:

CVE-2021-36222 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2021-36222 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2021-3711 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2021-3711 (SUSE): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2021-41174 (NVD) : 6.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:3676-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here