Outdated Grafana version
Nobody has claimed this yet.
- Dominant language
- Shell
- Stars
- 29
- Forks
- 46
- Avg merge
- 12h 51m
- Merged PRs (30d)
- 17
Description
Hey!
The current grafana version is fixed at v7.5.17. Renovate has tried to upgrade it but the PR has been closed.
v7.5.17 was released in 2022 and contains lots of CVEs (not limited to):
- CVE-2022-31107 — OAuth account takeover
- CVE-2022-35957 — Escalation to Server Admin when Auth Proxy is used
- CVE-2022-36062 — RBAC folder permission migration bug
- CVE-2022-31123 — Plugin signature verification bypass
- CVE-2022-31130 — Auth token leakage via data source/plugin proxy
- CVE-2022-39201 — Session/cookie leakage via proxy
- CVE-2022-39229 — “Email as username” can block other users’ login
- CVE-2022-39306 — Input validation bypass during invites/registration
- CVE-2022-39307 — User enumeration via “forgot password”
- CVE-2023-0594 — Stored XSS in TraceView
What are the paths forward from here? Is the upgrade planned anytime soon?
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by locating where Grafana v7.5.17 is pinned and review the closed Renovate PR #612 for prior upgrade context. Check the monitoring deployment and its validation process before selecting a supported version; done means the pinned version is upgraded and the monitoring setup remains functional without the listed vulnerabilities.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- grafana
- Domain
- observability
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100