Security update 5.1.1.1 for Multi-Linux Manager Client Tools
This update fixes the following issues: grafana was updated from version 11.5.7 to 11.5.10: - Security issues fixed: * CVE-2025-64751: Drop experimental implementation of authorization Zanzana server/client (version 11.5.10) (bsc#1254113) * CVE-2025-47911: Fix parsing HTML documents (version 11.5.10) (bsc#1251454) * CVE-2025-58190: Fix excessive memory consumption (version 11.5.10) (bsc#1251657) * CVE-2025-11065: Fixed sensitive information leak in logs (version 11.5.9) (bsc#1250616) - Other changes, new features and bugs fixed: * Version 11.5.10: + Use forked wire from Grafana repository instead of external package (jsc#PED-14178) + Auth: Fix render user OAuth passthrough. + LDAP Authentication: Fix URL to propagate username context as parameter. + Plugins: Dependencies do not inherit parent URL for preinstall. * Version 11.5.9: + Auditing: Document new options for recording datasource query request/response body. + Login: Fixed redirection after login when Grafana is served from subpath. * Update to version 11.5.8: + No relevant changes uyuni-tools: - version 5.1.23-0 * Update the default tag to 5.1.1.1 - version 5.1.22-0 * Fix cobbler config migration to standalone files * Fix generated DB certificate subject alternate names - version 5.1.21-0 * Remove extraneous quotes when getting the running image (bsc#1249434)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update fixes the following issues: grafana was updated from version 11.5.7 to 11.5.10: - Security issues fixed: * CVE-2025-64751: Drop experimental implementation of authorization Zanzana server/client (version 11.5.10) (bsc#1254113) * CVE-2025-47911: Fix parsing HTML documents (version 11.5.10) (bsc#1251454) * CVE-2025-58190: Fix excessive memory consumption (version 11.5.10) (bsc#1251657) * CVE-2025-11065: Fixed sensitive information leak in logs (version 11.5.9) (bsc#1250616) - Other changes, new features and bugs fixed: * Version 11.5.10: + Use forked wire from Grafana repository instead of external package (jsc#PED-14178) + Auth: Fix render user OAuth passthrough. + LDAP Authentication: Fix URL to propagate username context as parameter. + Plugins: Dependencies do not inherit parent URL for preinstall. * Version 11.5.9: + Auditing: Document new options for recording datasource query request/response body. + Login: Fixed redirection after login when Grafana is served from subpath. * Update to version 11.5.8: + No relevant changes uyuni-tools: - version 5.1.23-0 * Update the default tag to 5.1.1.1 - version 5.1.22-0 * Fix cobbler config migration to standalone files * Fix generated DB certificate subject alternate names - version 5.1.21-0 * Remove extraneous quotes when getting the running image (bsc#1249434)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1249434
- https://bugzilla.suse.com/1250616
- https://bugzilla.suse.com/1251454
- https://bugzilla.suse.com/1251657
- https://bugzilla.suse.com/1254113
- https://www.suse.com/security/cve/CVE-2025-11065
- https://www.suse.com/security/cve/CVE-2025-47911
- https://www.suse.com/security/cve/CVE-2025-58190
- https://www.suse.com/security/cve/CVE-2025-64751
- https://www.suse.com/support/update/announcement/2025/suse-su-20254446-1/