{"schema_version":"1.7.3","id":"SUSE-SU-2020:1273-1","published":"2020-05-13T14:23:49Z","modified":"2026-02-04T04:12:16.935952Z","related":["CVE-2018-12099","CVE-2018-15727","CVE-2018-19039","CVE-2018-558213","CVE-2019-13068","CVE-2019-15043"],"upstream":["CVE-2018-12099","CVE-2018-15727","CVE-2018-19039","CVE-2018-558213","CVE-2019-13068","CVE-2019-15043"],"summary":"Security update for grafana","details":"This update for grafana to version 4.6.5 fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2019-15043: Added authentication to a few rest endpoints (jsc#SOC-10357, bsc#1148383).\n- CVE-2018-19039: Fixed File Exfiltration vulnerability (jsc#SOC-9976 bsc#1115960).\n- CVE-2018-15727: Fixed an LDAP and OAuth login vulnerability (jsc#SOC-9980 bsc#1106515).\n- CVE-2018-12099: Fixed cross site scripting vulnerabilities in dashboard links (bsc#1096985).\n- CVE-2019-13068: Fixed an HTML injection in the panel drilldown links (bsc#1139862).\n\nNon-security issue fixed:\n\n- Solve wrongly categorized 'default.ini' file. (bsc#1167424)\n  The configuration file was wrongly classified as documentation instead of configuration file.\n  In systems where the documentation isn't installed by default was not possible to start the 'grafana server' service.\n","affected":[{"package":{"name":"grafana","ecosystem":"SUSE:Enterprise Storage 5","purl":"pkg:rpm/suse/grafana&distro=SUSE%20Enterprise%20Storage%205"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.6.5-3.10.1"}]}],"ecosystem_specific":{"binaries":[{"grafana":"4.6.5-3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:1273-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2020/suse-su-20201273-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1096985"},{"type":"REPORT","url":"https://bugzilla.suse.com/1106515"},{"type":"REPORT","url":"https://bugzilla.suse.com/1115960"},{"type":"REPORT","url":"https://bugzilla.suse.com/1139862"},{"type":"REPORT","url":"https://bugzilla.suse.com/1148383"},{"type":"REPORT","url":"https://bugzilla.suse.com/1167424"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12099"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-15727"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-19039"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-558213"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13068"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-15043"}]}