HomeFreeBSD

security/vuxml: Document Grafana multiple vulnerabilities

Description

security/vuxml: Document Grafana multiple vulnerabilities

  • CVE-2022-31123 - Plugin signature bypass
  • CVE-2022-31130 - Data source and plugin proxy endpoints leaking authentication tokens to some destination plugins
  • CVE-2022-39201 - Data source and plugin proxy endpoints leaking authentication tokens to some destination plugins
  • CVE-2022-39229 - Improper authentication
  • CVE-2022-39306 - Privilege escalation
  • CVE-2022-39307 - Username enumeration
  • CVE-2022-39328 - Privilege escalation (Critical)

https://grafana.com/blog/2022/10/12/grafana-security-releases-new-versions-with-fixes-for-cve-2022-39229-cve-2022-39201-cve-2022-31130-cve-2022-31123/
https://grafana.com/blog/2022/11/08/security-release-new-versions-of-grafana-with-critical-and-moderate-fixes-for-cve-2022-39328-cve-2022-39307-and-cve-2022-39306/

PR: 267728

Details

Provenance
drtr0jan_yandex.ruAuthored on Nov 12 2022, 9:26 PM
eduardoCommitted on Nov 13 2022, 12:18 AM
Parents
R11:c82c80d08ab6: x11/tofi: update to 0.7.0
Branches
Unknown
Tags
Unknown