{"schema_version":"1.7.5","id":"openSUSE-SU-2026:21351-1","published":"2026-07-14T09:22:23Z","modified":"2026-07-15T10:00:12.751955097Z","related":["CVE-2025-12141","CVE-2026-21725","CVE-2026-41607"],"upstream":["CVE-2025-12141","CVE-2026-21725","CVE-2026-41607"],"summary":"Security update for grafana","details":"This update for grafana fixes the following issues:\n\nChanges in grafana:\n\n- Add UI web assets as additional source tarball\n\n- Update to version 12.4.5 (jsc#PED-16512):\n  * Datasources: return 400 when payload UID does not match URL UID\n    in PUT /api/datasources/uid/:uid\n\n- Update to version 12.4.4:\n  * Security and quality updates.\n  * Various bug fixes and enhancements.\n\n- Update to version 12.4.3:\n  * Analytics: Keep internal dashboard id.\n  * Go: Update to 1.25.9.\n  * Reporting: Correctly apply appSubURL to report settings\n               requests.\n  * Alerting: Document Grafana HA Alertmanager cluster metrics\n              prefix change.\n\n- Update to version 12.4.2:\n  * Various bug fixes and performance improvements.\n  * Dependency updates to core plugins and UI libraries.\n\n- Update to version 12.4.1:\n  * Bug fixes and minor quality-of-life enhancements.\n  * Updates to data source provisioning and dashboard schemas.\n\n- Update to version 12.4.0:\n  * Introduced dynamic dashboards in public preview.\n  * Added a new side toolbar that replaces the second top toolbar\n    to provide additional vertical space.\n  * Added the ability to create dashboards from templates using\n    sample data.\n  * Revamped the gauge visualization with rounded bars,\n    configurable bar thickness, and endpoint markers.\n  * Added support to map one variable to multiple values.\n  * CVE-2025-12141: Fixed information leakage in Grafana Alerting\n    (bsc#1262187)\n\n- Update to version 12.3.0:\n  * Released a completely redesigned logs visualization.\n  * Added the ability to export dashboards directly as PNG images.\n  * Introduced an interactive learning experience within the\n    Grafana UI.\n  * Added a Switch template variable type to quickly toggle between\n    values in queries.\n  * Added functionality to style table cells using CSS properties\n    via the field cell option.\n\n- Update to version 12.2.0:\n  * Routine feature enhancements, minor bug fixes, and security\n    patches.\n\n- Update to version 12.1.0:\n  * Added support for Entra Workload Identity to enhance\n    authentication capabilities with federated credentials.\n  * Redesigned the alert rule list page.\n  * Renamed Mute Timings to Active Time Intervals in Grafana\n    Alerting.\n  * Added support for Service Account Impersonation in the BigQuery\n    data source.\n  * Introduced the Grafana Advisor in public preview.\n\n- Update to version 12.0.0:\n  * BREAKING: Removed AngularJS and all deprecated UI Extensions\n    APIs.\n  * BREAKING: Enforced stricter version compatibility checks in\n    plugin CLI install commands.\n  * BREAKING: Enabled the failWrongDSUID feature flag by default,\n    which rejects data sources with incorrect UIDs.\n  * MIGRATION: Triggered a full-table rewrite for the annotation\n    table, which may temporarily increase disk usage.\n  * Introduced a new dashboard schema to replace the original\n    single grid layout.\n\n- CVE-2026-41607: Fix potential information disclosure in Apache\n  Thrift (bsc#1263272)\n","affected":[{"package":{"name":"grafana","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/grafana&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.4.5-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"grafana":"12.4.5-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21351-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262187"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263272"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-12141"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21725"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41607"}]}