FlawAtlas
Search the atlas
SUSE-SU-2025:4446-1 Not scored

Security update 5.1.1.1 for Multi-Linux Manager Client Tools

This update fixes the following issues: grafana was updated from version 11.5.7 to 11.5.10: - Security issues fixed: * CVE-2025-64751: Drop experimental implementation of authorization Zanzana server/client (version 11.5.10) (bsc#1254113) * CVE-2025-47911: Fix parsing HTML documents (version 11.5.10) (bsc#1251454) * CVE-2025-58190: Fix excessive memory consumption (version 11.5.10) (bsc#1251657) * CVE-2025-11065: Fixed sensitive information leak in logs (version 11.5.9) (bsc#1250616) - Other changes, new features and bugs fixed: * Version 11.5.10: + Use forked wire from Grafana repository instead of external package (jsc#PED-14178) + Auth: Fix render user OAuth passthrough. + LDAP Authentication: Fix URL to propagate username context as parameter. + Plugins: Dependencies do not inherit parent URL for preinstall. * Version 11.5.9: + Auditing: Document new options for recording datasource query request/response body. + Login: Fixed redirection after login when Grafana is served from subpath. * Update to version 11.5.8: + No relevant changes uyuni-tools: - version 5.1.23-0 * Update the default tag to 5.1.1.1 - version 5.1.22-0 * Fix cobbler config migration to standalone files * Fix generated DB certificate subject alternate names - version 5.1.21-0 * Remove extraneous quotes when getting the running image (bsc#1249434)

Exploit probability Not scored
Published December 18, 2025
Required by Not available
Last source change March 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Multi Linux Manager Tools SLE-15 grafana
SUSE:Multi Linux Manager Tools SLE-15 uyuni-tools
SUSE:Multi Linux Manager Tools SLE-Micro-5 uyuni-tools

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:4446-1

This update fixes the following issues: grafana was updated from version 11.5.7 to 11.5.10: - Security issues fixed: * CVE-2025-64751: Drop experimental implementation of authorization Zanzana server/client (version 11.5.10) (bsc#1254113) * CVE-2025-47911: Fix parsing HTML documents (version 11.5.10) (bsc#1251454) * CVE-2025-58190: Fix excessive memory consumption (version 11.5.10) (bsc#1251657) * CVE-2025-11065: Fixed sensitive information leak in logs (version 11.5.9) (bsc#1250616) - Other changes, new features and bugs fixed: * Version 11.5.10: + Use forked wire from Grafana repository instead of external package (jsc#PED-14178) + Auth: Fix render user OAuth passthrough. + LDAP Authentication: Fix URL to propagate username context as parameter. + Plugins: Dependencies do not inherit parent URL for preinstall. * Version 11.5.9: + Auditing: Document new options for recording datasource query request/response body. + Login: Fixed redirection after login when Grafana is served from subpath. * Update to version 11.5.8: + No relevant changes uyuni-tools: - version 5.1.23-0 * Update the default tag to 5.1.1.1 - version 5.1.22-0 * Fix cobbler config migration to standalone files * Fix generated DB certificate subject alternate names - version 5.1.21-0 * Remove extraneous quotes when getting the running image (bsc#1249434)

View original source

05 / REFERENCES

Further evidence