{"id":"SUSE-SU-2025:01991-1","summary":"Security update for grafana","details":"This update for grafana fixes the following issues:\n\ngrafana was updated from version 10.4.15 to 11.5.5 (jsc#PED-12918):\n\n- Security issues fixed:\n    * CVE-2025-4123: Fix cross-site scripting vulnerability (bsc#1243714).\n    * CVE-2025-22872: Bump golang.org/x/net/html (bsc#1241809)\n    * CVE-2025-3580: Prevent unauthorized server admin deletion (bsc#1243672).\n    * CVE-2025-29923: Bump github.com/redis/go-redis/v9 to 9.6.3.\n    * CVE-2025-3454: Sanitize paths before evaluating access to route (bsc#1241683).\n    * CVE-2025-2703: Fix built-in XY Chart plugin (bsc#1241687).\n    * CVE-2025-22870: Bump golang.org/x/net (bsc#1238703).\n    * CVE-2024-9476: Fix Migration Assistant issue (bsc#1233343)\n    * CVE-2024-9264: SQL Expressions (bsc#1231844)\n    * CVE-2023-45288: Bump golang.org/x/net (bsc#1236510)\n    * CVE-2025-22870: Bump golang.org/x/net to version 0.37.0 (bsc#1238686)\n\n- Potential breaking changes in version 11.5.0:\n    * Loki: Default to /labels API with query param instead of /series API.\n- Potential breaking changes in version 11.0.1:\n    * If you had selected your language as 'Portugu�s Brasileiro'\n    previously, this will be reset. You have to select it again in\n    your Preferences for the fix to be applied and the translations\n    will then be shown.\n- Potential breaking changes in version 11.0.0:\n    * AngularJS support is turned off by default.\n    * Legacy alerting is entirely removed.\n    * Subfolders cause very rare issues with folders which have\n      slashes in their names.\n    * The input data source is removed.\n    * Data sources: Responses which are associated with hidden\n      queries will be removed (filtered) by Grafana.\n    * The URL which is generated when viewing an individual repeated\n      panel has changed.\n    * React Router is deprecated.\n    * The grafana/e2e testing tool is deprecated.\n    \n- This update brings many new features, enhancements and fixes highlighted at:\n  * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v11-5/\n  * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v11-4/\n  * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v11-3/\n  * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v11-2/\n  * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v11-1/\n  * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v11-0/\n","modified":"2026-02-04T03:37:00.058041Z","published":"2025-06-18T02:12:17Z","related":["CVE-2023-45288","CVE-2024-9264","CVE-2024-9476","CVE-2025-22870","CVE-2025-22872","CVE-2025-2703","CVE-2025-29923","CVE-2025-3454"],"upstream":["CVE-2023-45288","CVE-2024-9264","CVE-2024-9476","CVE-2025-22870","CVE-2025-22872","CVE-2025-2703","CVE-2025-29923","CVE-2025-3454"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2025/suse-su-202501991-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231844"},{"type":"REPORT","url":"https://bugzilla.suse.com/1233343"},{"type":"REPORT","url":"https://bugzilla.suse.com/1236510"},{"type":"REPORT","url":"https://bugzilla.suse.com/1236516"},{"type":"REPORT","url":"https://bugzilla.suse.com/1238686"},{"type":"REPORT","url":"https://bugzilla.suse.com/1238703"},{"type":"REPORT","url":"https://bugzilla.suse.com/1241683"},{"type":"REPORT","url":"https://bugzilla.suse.com/1241687"},{"type":"REPORT","url":"https://bugzilla.suse.com/1241809"},{"type":"REPORT","url":"https://bugzilla.suse.com/1243672"},{"type":"REPORT","url":"https://bugzilla.suse.com/1243714"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-45288"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-9264"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-9476"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22870"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22872"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-2703"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-29923"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-3454"}],"affected":[{"package":{"name":"grafana","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP6","purl":"pkg:rpm/suse/grafana&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.5.5-150200.3.72.2"}]}],"ecosystem_specific":{"binaries":[{"grafana":"11.5.5-150200.3.72.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:01991-1.json"}},{"package":{"name":"grafana","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/grafana&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.5.5-150200.3.72.2"}]}],"ecosystem_specific":{"binaries":[{"grafana":"11.5.5-150200.3.72.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:01991-1.json"}},{"package":{"name":"grafana","ecosystem":"openSUSE:Leap 15.6","purl":"pkg:rpm/opensuse/grafana&distro=openSUSE%20Leap%2015.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.5.5-150200.3.72.2"}]}],"ecosystem_specific":{"binaries":[{"grafana":"11.5.5-150200.3.72.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:01991-1.json"}}],"schema_version":"1.7.3"}