{"schema_version":"1.7.5","id":"SUSE-SU-2026:1524-1","published":"2026-04-21T09:26:09Z","modified":"2026-04-22T08:15:49.030922Z","related":["CVE-2025-13465","CVE-2025-3415","CVE-2025-61140","CVE-2026-1615","CVE-2026-21720","CVE-2026-21721","CVE-2026-21722","CVE-2026-21724","CVE-2026-21725","CVE-2026-25547","CVE-2026-26958","CVE-2026-27606","CVE-2026-27876","CVE-2026-27877","CVE-2026-27879","CVE-2026-28375","CVE-2026-33186"],"upstream":["CVE-2025-13465","CVE-2025-3415","CVE-2025-61140","CVE-2026-1615","CVE-2026-21720","CVE-2026-21721","CVE-2026-21722","CVE-2026-21724","CVE-2026-21725","CVE-2026-25547","CVE-2026-26958","CVE-2026-27606","CVE-2026-27876","CVE-2026-27877","CVE-2026-27879","CVE-2026-28375","CVE-2026-33186"],"summary":"Security update 5.1.3 for Multi-Linux Manager Client Tools","details":"This update fixes the following issues:\n\ngolang-github-lusitaniae-apache_exporter:\n\n- Internal changes to fix build issues with no impact for customers\n    \ngolang-github-prometheus-prometheus:\n\n- Security issues fixed:\n\n  * CVE-2026-27606: Fixed arbitrary file write via path traversal in rollup (bsc#1258893)\n    + Bumped rollup to version 4.59.0\n  * CVE-2026-25547: Fixed unbounded brace range expansion leading to excessive CPU and memory consumption (bsc#1257841)\n    + Bumped brace-expansion to version 5.0.2\n  * CVE-2026-1615, CVE-2025-61140 The old web UI is no longer built due to security issues (bsc#1257897, bsc#1257442)\n  * CVE-2025-13465: Bumped lodash package to version 4.17.23 to fix prototype pollution vulnerability (bsc#1257329)\n  * CVE-2026-33186: Fixed authorization bypass due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260267)\n    + Bumped google.golang.org/grpc to version 1.79.3\n    \n    \ngrafana:\n\n- Security issues fixed:\n\n  * CVE-2026-21722: Public dashboards annotations: use dashboard timerange if time selection disabled (bsc#1258136)\n  * CVE-2026-21721: Fixed access control by the dashboard permissions API (bsc#1257337)\n  * CVE-2026-21720: Fixed unauthenticated DoS (bsc#1257349)\n  * CVE-2025-3415: Fixed exposure of DingDing alerting integration URL to Viewer level users (bsc#1245302)\n  * CVE-2026-26958: Bumped filippo.io/edwards25519 to version 1.1.1 (bsc#1258595)\n  * CVE-2026-21725: Fixed missing UID when deleting datasource by name (bsc#1258873)\n  * CVE-2026-21725: Fixed missing UID when deleting datasource by name (bsc#1258873)\n  * CVE-2026-27876: Fixed remote arbitrary code execution via chained SQL Expressions (bsc#1261025)\n  * CVE-2026-27877: Fixed information disclosure of data-source passwords via public dashboards (bsc#1261026)\n  * CVE-2026-28375: Fixed denial of service via testdata data-source (bsc#1261029)\n  * CVE-2026-27879: Fixed denial of service via resample query (bsc#1261027)\n  * CVE-2026-33186: Fixed authorization bypass due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260263)\n  * CVE-2026-21724: Fixed authorization bypass allows modification of protected webhook URLs (bsc#1260878)\n\n- Version update from 11.5.10 to 11.6.14+security01 with the following highlighted changes and fixes:\n    \n  * Public Dashboards: Wired the public dashboard service to the HTTP server to ensure proper connectivity and availability\n  * Authentication: Refined the redirect logic to ensure consistent behavior during login and logout sequences\n  * Dashboard Reliability: Resolved a bug preventing single panels from rendering correctly when dashboard variables are referenced\n  * Performance Boost: Introduced WebGL-powered geomaps for smoother map visualizations and\n    removed blurred backgrounds from UI overlays to speed up the interface\n  * One-Click Actions: Visualizations now support faster navigation via one-click links and actions\n  * Alerting History: Added version history for alert rules, allowing you to track changes over time\n  * Service Accounts: Automated the migration of old API keys to more secure Service Accounts upon startup\n  * Cron Support: Annotations now support Cron syntax for more flexible scheduling\n  * Identity and Auth: Hardened the Avatar feature (now requires sign-in) and fixed several login redirection issues\n    when Grafana is hosted on a subpath\n  * Data Source Support: Added support for Cloud Partner Prometheus data sources and improved Azure legend formatting\n  * Alerting Limits: Added size limits for expanded notification templates to prevent system strain\n  * RBAC: Integrated Role-Based Access Control (RBAC) into the Alertmanager via the reqAction field\n  * Data Consistency: Fixed several issues with Graphite and InfluxDB regarding how variables are handled in repeated\n    rows or nested queries\n  * Dashboard Reliability: \n    + Fixed bugs involving row repeats and 'self-referencing' data links\n    + Fixed a bug preventing single panels from rendering correctly when dashboard variables are referenced\n  * Alerting Fixes: Patched a critical 'panic' (crash) caused by a race condition in alert rules and fixed issues where\n    contact points weren't working correctly\n  * URL Handling: Fixed a bug where 'true' values in URL parameters weren't being read correctly\n\nprometheus-blackbox_exporter:\n\n- Internal changes to fix build issues with no impact for customers\n\nspacecmd:\n\n- Version 5.1.13-0\n  * Update translation strings\n\nuyuni-tools:\n\n- Version 5.1.26-0\n  * Fixed applying PTF with images from RPMs (bsc#1252548)\n  * Ssl Key file can miss if CA password is blank (bsc#1254154)\n  * mgrpxy ssh tuning should happens before crypto policies (bsc#1254619)\n  * Fixed default value for helm registry (bsc#1258927).\n  * Remove hub register command\n  * Optimize postgres migration disk space usage (bsc#1257447)\n  * Added continuous database backup support (bsc#1250367)\n  * Explicitly start proxy pods after operations\n    (bsc#1258015)\n  * Use static supportconfig name to avoid dynamic search\n    (bsc#1257941)\n  * Do not nest multiple tarball files and instead collect\n    all files into one tarball (bsc#1252964)\n  * Show where final tarball was generated (bsc#1259208)\n  * Set proxy config file permissions (bsc#1257660)\n- Version 5.1.25-0\n  * If PTF image doesn't exists, use the current service image (bsc#1258418)\n\n","affected":[{"package":{"name":"golang-github-lusitaniae-apache_exporter","ecosystem":"SUSE:Multi Linux Manager Tools SLE-15","purl":"pkg:rpm/suse/golang-github-lusitaniae-apache_exporter&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.10-150002.3.6.1"}]}],"ecosystem_specific":{"binaries":[{"firewalld-prometheus-config":"0.1-150002.3.8.1","golang-github-lusitaniae-apache_exporter":"1.0.10-150002.3.6.1","golang-github-prometheus-prometheus":"3.5.0-150002.3.8.1","grafana":"11.6.14+security01-150002.4.14.1","mgrctl":"5.1.26-150002.3.12.1","mgrctl-bash-completion":"5.1.26-150002.3.12.1","mgrctl-lang":"5.1.26-150002.3.12.1","mgrctl-zsh-completion":"5.1.26-150002.3.12.1","prometheus-blackbox_exporter":"0.26.0-150002.3.6.1","spacecmd":"5.1.13-150002.3.9.3"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1524-1.json"}},{"package":{"name":"golang-github-prometheus-prometheus","ecosystem":"SUSE:Multi Linux Manager Tools SLE-15","purl":"pkg:rpm/suse/golang-github-prometheus-prometheus&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.5.0-150002.3.8.1"}]}],"ecosystem_specific":{"binaries":[{"firewalld-prometheus-config":"0.1-150002.3.8.1","golang-github-lusitaniae-apache_exporter":"1.0.10-150002.3.6.1","golang-github-prometheus-prometheus":"3.5.0-150002.3.8.1","grafana":"11.6.14+security01-150002.4.14.1","mgrctl":"5.1.26-150002.3.12.1","mgrctl-bash-completion":"5.1.26-150002.3.12.1","mgrctl-lang":"5.1.26-150002.3.12.1","mgrctl-zsh-completion":"5.1.26-150002.3.12.1","prometheus-blackbox_exporter":"0.26.0-150002.3.6.1","spacecmd":"5.1.13-150002.3.9.3"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1524-1.json"}},{"package":{"name":"grafana","ecosystem":"SUSE:Multi Linux Manager Tools SLE-15","purl":"pkg:rpm/suse/grafana&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.6.14+security01-150002.4.14.1"}]}],"ecosystem_specific":{"binaries":[{"firewalld-prometheus-config":"0.1-150002.3.8.1","golang-github-lusitaniae-apache_exporter":"1.0.10-150002.3.6.1","golang-github-prometheus-prometheus":"3.5.0-150002.3.8.1","grafana":"11.6.14+security01-150002.4.14.1","mgrctl":"5.1.26-150002.3.12.1","mgrctl-bash-completion":"5.1.26-150002.3.12.1","mgrctl-lang":"5.1.26-150002.3.12.1","mgrctl-zsh-completion":"5.1.26-150002.3.12.1","prometheus-blackbox_exporter":"0.26.0-150002.3.6.1","spacecmd":"5.1.13-150002.3.9.3"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1524-1.json"}},{"package":{"name":"prometheus-blackbox_exporter","ecosystem":"SUSE:Multi Linux Manager Tools SLE-15","purl":"pkg:rpm/suse/prometheus-blackbox_exporter&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26.0-150002.3.6.1"}]}],"ecosystem_specific":{"binaries":[{"firewalld-prometheus-config":"0.1-150002.3.8.1","golang-github-lusitaniae-apache_exporter":"1.0.10-150002.3.6.1","golang-github-prometheus-prometheus":"3.5.0-150002.3.8.1","grafana":"11.6.14+security01-150002.4.14.1","mgrctl":"5.1.26-150002.3.12.1","mgrctl-bash-completion":"5.1.26-150002.3.12.1","mgrctl-lang":"5.1.26-150002.3.12.1","mgrctl-zsh-completion":"5.1.26-150002.3.12.1","prometheus-blackbox_exporter":"0.26.0-150002.3.6.1","spacecmd":"5.1.13-150002.3.9.3"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1524-1.json"}},{"package":{"name":"spacecmd","ecosystem":"SUSE:Multi Linux Manager Tools SLE-15","purl":"pkg:rpm/suse/spacecmd&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.1.13-150002.3.9.3"}]}],"ecosystem_specific":{"binaries":[{"firewalld-prometheus-config":"0.1-150002.3.8.1","golang-github-lusitaniae-apache_exporter":"1.0.10-150002.3.6.1","golang-github-prometheus-prometheus":"3.5.0-150002.3.8.1","grafana":"11.6.14+security01-150002.4.14.1","mgrctl":"5.1.26-150002.3.12.1","mgrctl-bash-completion":"5.1.26-150002.3.12.1","mgrctl-lang":"5.1.26-150002.3.12.1","mgrctl-zsh-completion":"5.1.26-150002.3.12.1","prometheus-blackbox_exporter":"0.26.0-150002.3.6.1","spacecmd":"5.1.13-150002.3.9.3"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1524-1.json"}},{"package":{"name":"uyuni-tools","ecosystem":"SUSE:Multi Linux Manager Tools SLE-15","purl":"pkg:rpm/suse/uyuni-tools&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.1.26-150002.3.12.1"}]}],"ecosystem_specific":{"binaries":[{"firewalld-prometheus-config":"0.1-150002.3.8.1","golang-github-lusitaniae-apache_exporter":"1.0.10-150002.3.6.1","golang-github-prometheus-prometheus":"3.5.0-150002.3.8.1","grafana":"11.6.14+security01-150002.4.14.1","mgrctl":"5.1.26-150002.3.12.1","mgrctl-bash-completion":"5.1.26-150002.3.12.1","mgrctl-lang":"5.1.26-150002.3.12.1","mgrctl-zsh-completion":"5.1.26-150002.3.12.1","prometheus-blackbox_exporter":"0.26.0-150002.3.6.1","spacecmd":"5.1.13-150002.3.9.3"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1524-1.json"}},{"package":{"name":"prometheus-blackbox_exporter","ecosystem":"SUSE:Multi Linux Manager Tools SLE-Micro-5","purl":"pkg:rpm/suse/prometheus-blackbox_exporter&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-Micro-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26.0-150002.3.6.1"}]}],"ecosystem_specific":{"binaries":[{"mgrctl":"5.1.26-150002.3.12.1","mgrctl-bash-completion":"5.1.26-150002.3.12.1","mgrctl-lang":"5.1.26-150002.3.12.1","mgrctl-zsh-completion":"5.1.26-150002.3.12.1","prometheus-blackbox_exporter":"0.26.0-150002.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1524-1.json"}},{"package":{"name":"uyuni-tools","ecosystem":"SUSE:Multi Linux Manager Tools SLE-Micro-5","purl":"pkg:rpm/suse/uyuni-tools&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-Micro-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.1.26-150002.3.12.1"}]}],"ecosystem_specific":{"binaries":[{"mgrctl":"5.1.26-150002.3.12.1","mgrctl-bash-completion":"5.1.26-150002.3.12.1","mgrctl-lang":"5.1.26-150002.3.12.1","mgrctl-zsh-completion":"5.1.26-150002.3.12.1","prometheus-blackbox_exporter":"0.26.0-150002.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1524-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261524-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1245302"},{"type":"REPORT","url":"https://bugzilla.suse.com/1250367"},{"type":"REPORT","url":"https://bugzilla.suse.com/1252548"},{"type":"REPORT","url":"https://bugzilla.suse.com/1252964"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254154"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254619"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257329"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257337"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257349"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257442"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257447"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257660"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257841"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257897"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257941"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258015"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258136"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258418"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258595"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258873"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258893"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258927"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259208"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260263"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260267"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260878"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261025"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261026"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261027"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261029"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-13465"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-3415"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-61140"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1615"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21720"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21721"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21722"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21724"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21725"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25547"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26958"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27606"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27876"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27877"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27879"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28375"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33186"}]}