Navigation Menu

Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

UPGRADE: Grafana to 8.2.3 #5852

Closed
hacker0ni opened this issue Oct 12, 2021 · 2 comments
Closed

UPGRADE: Grafana to 8.2.3 #5852

hacker0ni opened this issue Oct 12, 2021 · 2 comments
Assignees
Labels

Comments

@hacker0ni
Copy link
Contributor

hacker0ni commented Oct 12, 2021

The latest version of Grafana in Security Onion 2.3.80 is v7.5.4. This version is affected by an improper authentication access bug, which is fixed in 7.5.11+ or 8.1.6+. Could you please update this component in a new version?

CVE-2021-39226 - Grafana Improper Auth Access

@dougburks dougburks changed the title CVE-2021-39226 Grafana Improper Auth Access UPGRADE: Grafana due to CVE-2021-39226 Grafana Improper Auth Access Oct 12, 2021
@TOoSmOotH TOoSmOotH added the must label Oct 12, 2021
@jertel jertel changed the title UPGRADE: Grafana due to CVE-2021-39226 Grafana Improper Auth Access UPGRADE: Grafana to 8.2.1; Fixes CVE-2021-39226 Grafana Improper Auth Access Oct 18, 2021
@jertel
Copy link
Contributor

jertel commented Oct 18, 2021

Note that Security Onion does not utilize Grafana authentication, instead preferring the SOC proxy authentication fronting anonymouse Grafana access, so the referenced CVE should not have an impact to this or prior SO releases.

@jertel jertel self-assigned this Oct 18, 2021
@jertel jertel changed the title UPGRADE: Grafana to 8.2.1; Fixes CVE-2021-39226 Grafana Improper Auth Access UPGRADE: Grafana to 8.2.1 Oct 19, 2021
@TOoSmOotH TOoSmOotH changed the title UPGRADE: Grafana to 8.2.1 UPGRADE: Grafana to 8.2.3 Nov 8, 2021
@TOoSmOotH
Copy link
Contributor

Upgrading to 8.2.3 due to: GHSA-3j9m-hcv9-rpj8

@jertel jertel closed this as completed Nov 8, 2021
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Mar 8, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

3 participants