Release grafana-10.2.6-17.el10_0 ALSA-2025:7892
- Dominant language
- No language data
- Stars
- 2
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
grafana security update
Severity: Important
Description
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.
Security Fix(es):
* grafana: Cross-site Scripting (XSS) in Grafana via Custom Frontend Plugins and Open Redirect (CVE-2025-4123)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected packages:
grafana-10.2.6-17.el10_0.x86_64
grafana-selinux-10.2.6-17.el10_0.x86_64
grafana-10.2.6-17.el10_0.s390x
grafana-selinux-10.2.6-17.el10_0.s390x
grafana-10.2.6-17.el10_0.ppc64le
grafana-selinux-10.2.6-17.el10_0.ppc64le
grafana-10.2.6-17.el10_0.aarch64
grafana-selinux-10.2.6-17.el10_0.aarch64
Contributor guide
Assessment
This issue has not been assessed yet.