Skip to content

[Bug][grafana] current grafana version 9.5.2 authentication bypass vulnerability #6456

@iwasserr

Description

@iwasserr

Search before asking

  • I had searched in the issues and found no similar issues.

What happened

our internal qualy scan reports a grafana authentication bypass vulnerability
Grafana has released patch addressing the issue. For more information please refer to Grafana Security Advisory(https://grafana.com/blog/2023/...-cve-2023-3128/)
Patch: Following are links for downloading patches to fix the vulnerabilities:Grafana Security Advisory (https://grafana.com/blog/2023/...-cve-2023-3128/)

What do you expect to happen

due to my investigations this can be fixed by using grafana version 9.5.5 or higher
I expect a change of the used dockerfile
https://github.com/apache/incubator-devlake/blob/main/grafana/Dockerfile#L26
FROM grafana/grafana:9.5.5

How to reproduce

please see also
https://grafana.com/blog/2023/06/22/grafana-security-release-for-cve-2023-3128/

Anything else

No response

Version

v0.19.0-beta6

Are you willing to submit PR?

  • Yes I am willing to submit a PR!

Code of Conduct

Metadata

Metadata

Assignees

Labels

type/bugThis issue is a bug

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions