FlawAtlas
Search the atlas
SUSE-SU-2023:0821-1 Not scored

Security update for grafana

This update for grafana fixes the following issues: - CVE-2022-23552: Fixed SVG processing by adding a dompurify preprocessor step (bsc#1207749). - CVE-2022-39324: Fixed originalUrl spoof security issue (bsc#1207750). - CVE-2022-41723: Fixed go issue to avoid quadratic complexity in HPACK decoding (bsc#1208293). - CVE-2022-46146: Fixed basic authentication bypass by updating the exporter toolkit (bsc#1208065). - Trim leading and trailing whitespaces from email and username on signup - Fix invitation validation: Check whether the provided email address is the same as where the invitation is sent

Exploit probability Not scored
Published March 20, 2023
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Module for Package Hub 15 SP4 grafana
openSUSE:Leap 15.4 grafana

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2023:0821-1

This update for grafana fixes the following issues: - CVE-2022-23552: Fixed SVG processing by adding a dompurify preprocessor step (bsc#1207749). - CVE-2022-39324: Fixed originalUrl spoof security issue (bsc#1207750). - CVE-2022-41723: Fixed go issue to avoid quadratic complexity in HPACK decoding (bsc#1208293). - CVE-2022-46146: Fixed basic authentication bypass by updating the exporter toolkit (bsc#1208065). - Trim leading and trailing whitespaces from email and username on signup - Fix invitation validation: Check whether the provided email address is the same as where the invitation is sent

View original source

05 / REFERENCES

Further evidence