pingcap / pingcap/monitoring

Outdated Grafana version

Open
#901 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

contribution first-time-contributor
Dominant language
Shell
Stars
29
Forks
46
Avg merge
12h 51m
Merged PRs (30d)
17

Description

Hey!

The current grafana version is fixed at v7.5.17. Renovate has tried to upgrade it but the PR has been closed.

v7.5.17 was released in 2022 and contains lots of CVEs (not limited to):

  • CVE-2022-31107 — OAuth account takeover
  • CVE-2022-35957 — Escalation to Server Admin when Auth Proxy is used
  • CVE-2022-36062 — RBAC folder permission migration bug
  • CVE-2022-31123 — Plugin signature verification bypass
  • CVE-2022-31130 — Auth token leakage via data source/plugin proxy
  • CVE-2022-39201 — Session/cookie leakage via proxy
  • CVE-2022-39229 — “Email as username” can block other users’ login
  • CVE-2022-39306 — Input validation bypass during invites/registration
  • CVE-2022-39307 — User enumeration via “forgot password”
  • CVE-2023-0594 — Stored XSS in TraceView

What are the paths forward from here? Is the upgrade planned anytime soon?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating where Grafana v7.5.17 is pinned and review the closed Renovate PR #612 for prior upgrade context. Check the monitoring deployment and its validation process before selecting a supported version; done means the pinned version is upgraded and the monitoring setup remains functional without the listed vulnerabilities.

Written by the indexing model from the issue text.

Assessment

Tech stack
grafana
Domain
observability
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.