FlawAtlas
Search the atlas
SUSE-SU-2023:3886-1 Not scored

Security update for grafana

This update for grafana fixes the following issues: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version.

Exploit probability Not scored
Published September 28, 2023
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Module for Package Hub 15 SP4 grafana
SUSE:Linux Enterprise Module for Package Hub 15 SP5 grafana
openSUSE:Leap 15.4 grafana
openSUSE:Leap 15.5 grafana

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2023:3886-1

This update for grafana fixes the following issues: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version.

View original source

05 / REFERENCES

Further evidence