<div class="container">
<h1>Security update for grafana</h1>
<table class="table table-striped table-bordered">
<tbody>
<tr>
<th>Announcement ID:</th>
<td>SUSE-SU-2023:2916-1</td>
</tr>
<tr>
<th>Rating:</th>
<td>critical</td>
</tr>
<tr>
<th>References:</th>
<td>
<ul>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1212099">#1212099</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1212100">#1212100</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1212641">#1212641</a>
</li>
</ul>
</td>
</tr>
<tr>
<th>
Cross-References:
</th>
<td>
<ul>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2023-2183.html">CVE-2023-2183</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2023-2801.html">CVE-2023-2801</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2023-3128.html">CVE-2023-3128</a>
</li>
</ul>
</td>
</tr>
<tr>
<th>CVSS scores:</th>
<td>
<ul class="list-group">
<li class="list-group-item">
<span class="cvss-reference">CVE-2023-2183</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">4.1</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2023-2183</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">4.1</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2023-2801</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">7.5</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2023-2801</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">7.5</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2023-3128</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">9.4</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2023-3128</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">9.4</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L</span>
</li>
</ul>
</td>
</tr>
<tr>
<th>Affected Products:</th>
<td>
<ul class="list-group">
<li class="list-group-item">SUSE Linux Enterprise Desktop 12</li>
<li class="list-group-item">SUSE Linux Enterprise Desktop 12 SP1</li>
<li class="list-group-item">SUSE Linux Enterprise Desktop 12 SP2</li>
<li class="list-group-item">SUSE Linux Enterprise Desktop 12 SP3</li>
<li class="list-group-item">SUSE Linux Enterprise Desktop 12 SP4</li>
<li class="list-group-item">SUSE Linux Enterprise High Performance Computing 12 SP2</li>
<li class="list-group-item">SUSE Linux Enterprise High Performance Computing 12 SP3</li>
<li class="list-group-item">SUSE Linux Enterprise High Performance Computing 12 SP4</li>
<li class="list-group-item">SUSE Linux Enterprise High Performance Computing 12 SP5</li>
<li class="list-group-item">SUSE Linux Enterprise Server 12</li>
<li class="list-group-item">SUSE Linux Enterprise Server 12 SP1</li>
<li class="list-group-item">SUSE Linux Enterprise Server 12 SP2</li>
<li class="list-group-item">SUSE Linux Enterprise Server 12 SP3</li>
<li class="list-group-item">SUSE Linux Enterprise Server 12 SP4</li>
<li class="list-group-item">SUSE Linux Enterprise Server 12 SP5</li>
<li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 12</li>
<li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 12 SP1</li>
<li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 12 SP2</li>
<li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 12 SP3</li>
<li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 12 SP4</li>
<li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 12 SP5</li>
<li class="list-group-item">SUSE Linux Enterprise Server for the Raspberry Pi 12-SP2</li>
<li class="list-group-item">SUSE Manager Client Tools for SLE 12</li>
</ul>
</td>
</tr>
</tbody>
</table>
<p>An update that solves three vulnerabilities and contains two features can now be installed.</p>
<h2>Description:</h2>
<p>This update fixes the following issues:</p>
<p>grafana:</p>
<ul>
<li>Update to version 9.5.5:</li>
<li>CVE-2023-3128: Fix authentication bypass using Azure AD OAuth (bsc#1212641, jsc#PED-3694)</li>
<li>Bug fixes:<ul>
<li>Auth: Show invite button if disable login form is set to false.</li>
<li>Azure: Fix Kusto auto-completion for Azure datasources.</li>
<li>RBAC: Remove legacy AC editor and admin role on new dashboard route.</li>
<li>API: Revert allowing editors to access GET /datasources. </li>
<li>Settings: Add ability to override skip_org_role_sync with Env variables.</li>
</ul>
</li>
<li>Update to version 9.5.3:</li>
<li>CVE-2023-2801: Query: Prevent crash while executing concurrent mixed queries (bsc#1212099)</li>
<li>CVE-2023-2183: Alerting: Require alert.notifications:write permissions to test receivers and templates (bsc#1212100)</li>
<li>Update to version 9.5.2:
Alerting: Scheduler use rule fingerprint instead of version.
Explore: Update table min height.
DataLinks: Encoded URL fixed.
TimeSeries: Fix leading null-fill for missing intervals.
Dashboard: Revert fixed header shown on mobile devices in the new panel header.
PostgreSQL: Fix TLS certificate issue by downgrading lib/pq.
Provisioning: Fix provisioning issues with legacy alerting and data source permissions.
Alerting: Fix misleading status code in provisioning API.
Loki: Fix log samples using <code>instant</code> queries.
Panel Header: Implement new Panel Header on Angular Panels.
Azure Monitor: Fix bug that was not showing resources for certain locations.
Alerting: Fix panic when reparenting receivers to groups following an attempted rename via Provisioning.
Cloudwatch Logs: Clarify Cloudwatch Logs Limits.</li>
<li>Update to 9.5.1
Loki Variable Query Editor: Fix bug when the query is updated
Expressions: Fix expression load with legacy UID -100</li>
</ul>
<h2>Patch Instructions:</h2>
<p>
To install this SUSE Critical update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".<br/>
Alternatively you can run the command listed for your product:
</p>
<ul class="list-group">
<li class="list-group-item">
SUSE Manager Client Tools for SLE 12
<br/>
<code>zypper in -t patch SUSE-SLE-Manager-Tools-12-2023-2916=1</code>
</li>
</ul>
<h2>Package List:</h2>
<ul>
<li>
SUSE Manager Client Tools for SLE 12 (aarch64 ppc64le s390x x86_64)
<ul>
<li>grafana-9.5.5-1.51.1</li>
</ul>
</li>
</ul>
<h2>References:</h2>
<ul>
<li>
<a href="https://www.suse.com/security/cve/CVE-2023-2183.html">https://www.suse.com/security/cve/CVE-2023-2183.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2023-2801.html">https://www.suse.com/security/cve/CVE-2023-2801.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2023-3128.html">https://www.suse.com/security/cve/CVE-2023-3128.html</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1212099">https://bugzilla.suse.com/show_bug.cgi?id=1212099</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1212100">https://bugzilla.suse.com/show_bug.cgi?id=1212100</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1212641">https://bugzilla.suse.com/show_bug.cgi?id=1212641</a>
</li>
<li>
<a href="https://jira.suse.com/browse/MSQA-687">https://jira.suse.com/browse/MSQA-687</a>
</li>
<li>
<a href="https://jira.suse.com/browse/PED-3694">https://jira.suse.com/browse/PED-3694</a>
</li>
</ul>
</div>