Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
100

SUSE 15: Security Update for Grafana Snapshot Bypass and Markdown Traversal

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for grafana ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0139-1 Rating: important References: #1191454 #1193688 Cross-References: CVE-2021-39226 CVE-2021-43813 CVSS scores: CVE-2021-39226 (NVD) : 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVE-2021-39226 (SUSE): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVE-2021-43813 (NVD) : 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVE-2021-43813 (SUSE): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Affected Products: SUSE Manager Tools 15 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for grafana fixes the following issues: - CVE-2021-39226: Fixed snapshot authentication bypass (bsc#1191454) - CVE-2021-43813: Fixed markdown path traversal (bsc#1193688) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Tools 15: zypper in -t patch SUSE-SLE-Manager-Tools-15-2022-139=1 Package List: - SUSE Manager Tools 15 (aarch64 ppc64le s390x x86_64): grafana-7.5.12-1.27.1 References: https://www.suse.com/security/cve/CVE-2021-39226.html https://www.suse.com/security/cve/CVE-2021-43813.html https://bugzilla.suse.com/1191454 https://bugzilla.suse.com/1193688 . SUSE Security Patch: Critical grafana enhancements address snapshot evasion and markdown path traversal flaws.. SUSE Security Update,Grafana Update,Snapshot Bypass Fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 20, 2022 Important SuSE
100

SUSE: 2022:0138-1 Important: Grafana Snapshot Bypass And Path Traversal

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for grafana ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0138-1 Rating: important References: #1191454 #1193688 Cross-References: CVE-2021-39226 CVE-2021-43813 CVSS scores: CVE-2021-39226 (NVD) : 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVE-2021-39226 (SUSE): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVE-2021-43813 (NVD) : 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVE-2021-43813 (SUSE): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Affected Products: SUSE Manager Tools 12 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for grafana fixes the following issues: - CVE-2021-39226: Fixed snapshot authentication bypass (bsc#1191454) - CVE-2021-43813: Fixed markdown path traversal (bsc#1193688) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Tools 12: zypper in -t patch SUSE-SLE-Manager-Tools-12-2022-138=1 Package List: - SUSE Manager Tools 12 (aarch64 ppc64le s390x x86_64): grafana-7.5.12-1.27.1 References: https://www.suse.com/security/cve/CVE-2021-39226.html https://www.suse.com/security/cve/CVE-2021-43813.html https://bugzilla.suse.com/1191454 https://bugzilla.suse.com/1193688 . SUSE has issued a critical security patch for Grafana addressing severe vulnerabilities such as snapshot bypass and directory traversal.. SUSE Manager, Grafana Security, Patch Instructions. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 20, 2022 Important SuSE
98

Red Hat Enterprise Linux: RHSA-2021-3769-01 Important Grafana Update

An update for grafana is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: grafana security update Advisory ID: RHSA-2021:3769-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:3769 Issue date: 2021-10-12 CVE Names: CVE-2021-39226 ==================================================================== 1. Summary: An update for grafana is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v. 8.1) - aarch64, ppc64le, s390x, x86_64 3. Description: Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): * grafana: Snapshot authentication bypass (CVE-2021-39226) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2011063 - CVE-2021-39226 grafana: Snapshot authentication bypass 6. Package List: Red Hat Enterprise Linux AppStream EUS (v.8.1): Source: grafana-6.2.2-7.el8_1.src.rpm aarch64: grafana-6.2.2-7.el8_1.aarch64.rpm grafana-azure-monitor-6.2.2-7.el8_1.aarch64.rpm grafana-cloudwatch-6.2.2-7.el8_1.aarch64.rpm grafana-debuginfo-6.2.2-7.el8_1.aarch64.rpm grafana-elasticsearch-6.2.2-7.el8_1.aarch64.rpm grafana-graphite-6.2.2-7.el8_1.aarch64.rpm grafana-influxdb-6.2.2-7.el8_1.aarch64.rpm grafana-loki-6.2.2-7.el8_1.aarch64.rpm grafana-mssql-6.2.2-7.el8_1.aarch64.rpm grafana-mysql-6.2.2-7.el8_1.aarch64.rpm grafana-opentsdb-6.2.2-7.el8_1.aarch64.rpm grafana-postgres-6.2.2-7.el8_1.aarch64.rpm grafana-prometheus-6.2.2-7.el8_1.aarch64.rpm grafana-stackdriver-6.2.2-7.el8_1.aarch64.rpm ppc64le: grafana-6.2.2-7.el8_1.ppc64le.rpm grafana-azure-monitor-6.2.2-7.el8_1.ppc64le.rpm grafana-cloudwatch-6.2.2-7.el8_1.ppc64le.rpm grafana-debuginfo-6.2.2-7.el8_1.ppc64le.rpm grafana-elasticsearch-6.2.2-7.el8_1.ppc64le.rpm grafana-graphite-6.2.2-7.el8_1.ppc64le.rpm grafana-influxdb-6.2.2-7.el8_1.ppc64le.rpm grafana-loki-6.2.2-7.el8_1.ppc64le.rpm grafana-mssql-6.2.2-7.el8_1.ppc64le.rpm grafana-mysql-6.2.2-7.el8_1.ppc64le.rpm grafana-opentsdb-6.2.2-7.el8_1.ppc64le.rpm grafana-postgres-6.2.2-7.el8_1.ppc64le.rpm grafana-prometheus-6.2.2-7.el8_1.ppc64le.rpm grafana-stackdriver-6.2.2-7.el8_1.ppc64le.rpm s390x: grafana-6.2.2-7.el8_1.s390x.rpm grafana-azure-monitor-6.2.2-7.el8_1.s390x.rpm grafana-cloudwatch-6.2.2-7.el8_1.s390x.rpm grafana-debuginfo-6.2.2-7.el8_1.s390x.rpm grafana-elasticsearch-6.2.2-7.el8_1.s390x.rpm grafana-graphite-6.2.2-7.el8_1.s390x.rpm grafana-influxdb-6.2.2-7.el8_1.s390x.rpm grafana-loki-6.2.2-7.el8_1.s390x.rpm grafana-mssql-6.2.2-7.el8_1.s390x.rpm grafana-mysql-6.2.2-7.el8_1.s390x.rpm grafana-opentsdb-6.2.2-7.el8_1.s390x.rpm grafana-postgres-6.2.2-7.el8_1.s390x.rpm grafana-prometheus-6.2.2-7.el8_1.s390x.rpm grafana-stackdriver-6.2.2-7.el8_1.s390x.rpm x86_64: grafana-6.2.2-7.el8_1.x86_64.rpm grafana-azure-monitor-6.2.2-7.el8_1.x86_64.rpm grafana-cloudwatch-6.2.2-7.el8_1.x86_64.rpm grafana-debuginfo-6.2.2-7.el8_1.x86_64.rpm grafana-elasticsearch-6.2.2-7.el8_1.x86_64.rpm grafana-graphite-6.2.2-7.el8_1.x86_64.rpm grafana-influxdb-6.2.2-7.el8_1.x86_64.rpm grafana-loki-6.2.2-7.el8_1.x86_64.rpm grafana-mssql-6.2.2-7.el8_1.x86_64.rpm grafana-mysql-6.2.2-7.el8_1.x86_64.rpm grafana-opentsdb-6.2.2-7.el8_1.x86_64.rpm grafana-postgres-6.2.2-7.el8_1.x86_64.rpm grafana-prometheus-6.2.2-7.el8_1.x86_64.rpm grafana-stackdriver-6.2.2-7.el8_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-39226 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYWVnL9zjgjWX9erEAQjVahAAoJ7+9AngYZM5PDdO2kvnwX3knbZLlvpU yhDQEIDnv0Q3RGFKybww186KdEGOJCrhSKjVgdMtaP6Ksm7GHaIbm4b5myqTxvHN Q8mTbM7XyUeEOvKKjOwRYapWFjtssA1zDJDxWLUTulJrzFGlW2yl4x+c3nZLypli 6Sgps3Oa37wft1J/IpA8Tlyq0LcVpQ/xyKdN64CTyT7o54MU0TttuwPgsU/XsGmw grmuFv26CSpXW+F+2vO/BmCxdDIO3e5+ZZ8vvjRCM7FL4EVOXZW59lmv/7sqa9OS QrMM5Lt4LawxpwGN8bkDLhIz4oPYmUtlXSqEbryCCh37/PUbToP70ZICj+B77OFB QMvOcGQ6EdSu1cHMPzPZCzXm+twOMu+d3Drb1lxXSI7JLuLWIODYVEo01zPm5Z6M YtLL1oW6dRaL1bJ5EvzNuazPz4nOuIoNQBrJycjc6aOEhUfDFe2srq4L3DO+UhZ0 RUdE3/EJdvVvLZt9X5Z1BVL9KvDmrSEHuPd6cUN31YuIraSQozVXW6j3v/tiOG+D lvnjzueupji80QuD2h2vTiUQAgVEOXmiGdONJTFSzE3DqOZ9kiMIqVp7YkH6+qem Z3mhnt0plyQRL1rJCZA1EKJUGQBr0TF1ld3rTGbGj9Z8iwSa26/wiJCqd7EzAt1O vh1z8o0ZYj0=UOrO -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical patch released for Grafana, classified as high priority, resolving login vulnerabilities. Red Hat users can access the update now.. grafana security, red hat update, snapshot authentication bypass, security fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 12, 2021 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here