Security update for grafana
This update for grafana fixes the following issues: Updated to version 8.3.10 (jsc#SLE-24565, jsc#SLE-23422, jsc#SLE-23439): - CVE-2022-31097: Fixed XSS vulnerability in the Unified Alerting (bsc#1201535). - CVE-2022-31107: Fixed OAuth account takeover vulnerability (bsc#1201539). - CVE-2022-21702: Fixed XSS through attacker-controlled data source (bsc#1195726). - CVE-2022-21703: Fixed Cross Site Request Forgery (bsc#1195727). - CVE-2022-21713: Fixed Teams API IDOR (bsc#1195728).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for grafana fixes the following issues: Updated to version 8.3.10 (jsc#SLE-24565, jsc#SLE-23422, jsc#SLE-23439): - CVE-2022-31097: Fixed XSS vulnerability in the Unified Alerting (bsc#1201535). - CVE-2022-31107: Fixed OAuth account takeover vulnerability (bsc#1201539). - CVE-2022-21702: Fixed XSS through attacker-controlled data source (bsc#1195726). - CVE-2022-21703: Fixed Cross Site Request Forgery (bsc#1195727). - CVE-2022-21713: Fixed Teams API IDOR (bsc#1195728).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1195726
- https://bugzilla.suse.com/1195727
- https://bugzilla.suse.com/1195728
- https://bugzilla.suse.com/1201535
- https://bugzilla.suse.com/1201539
- https://www.suse.com/security/cve/CVE-2022-21702
- https://www.suse.com/security/cve/CVE-2022-21703
- https://www.suse.com/security/cve/CVE-2022-21713
- https://www.suse.com/security/cve/CVE-2022-31097
- https://www.suse.com/security/cve/CVE-2022-31107
- https://www.suse.com/support/update/announcement/2022/suse-su-20223765-1/