diff --git a/_service b/_service index 7d1b402..63b0d0d 100644 --- a/_service +++ b/_service @@ -5,7 +5,7 @@ .git @PARENT_TAG@ v(.*) - v8.5.14 + v8.5.15 enable diff --git a/_servicedata b/_servicedata index a809f9c..8f07a9f 100644 --- a/_servicedata +++ b/_servicedata @@ -1,6 +1,6 @@ https://github.com/grafana/grafana - 5bc88988a5a25c23452249315e8789ef059a2a3d + be4228db5a43f65a989239f891185d45912d39ad \ No newline at end of file diff --git a/grafana-8.5.14.tar.gz b/grafana-8.5.14.tar.gz deleted file mode 100644 index 66cb3db..0000000 --- a/grafana-8.5.14.tar.gz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:a3a0e0161d454cb2585f0d5ebc58ada4c93420ea1c5bd6db5a1a42d0e93b9b8b -size 51535752 diff --git a/grafana-8.5.15.tar.gz b/grafana-8.5.15.tar.gz new file mode 100644 index 0000000..665622f --- /dev/null +++ b/grafana-8.5.15.tar.gz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:fcdcdbb5021344ee8f21decd8cfaac7c23928385fe0f7d550cb795ceab5cead1 +size 51544910 diff --git a/grafana.changes b/grafana.changes index 296e7f3..c338d97 100644 --- a/grafana.changes +++ b/grafana.changes @@ -1,7 +1,16 @@ +------------------------------------------------------------------- +Fri Nov 18 10:52:52 UTC 2022 - witold.bedyk@suse.com + +- Update to version 8.5.15 (jsc#PED-2617): + * Security: Fix for privilege escalation + (bsc#1205225, CVE-2022-3930) + * Security: Omit error from http response when user does not + exists (bsc#1205227, CVE-2022-39307) + ------------------------------------------------------------------- Fri Nov 11 09:06:30 UTC 2022 - witold.bedyk@suse.com -- Update to version 8.5.14 (jsc#PED-2617): +- Update to version 8.5.14: * Security: Fix do not forward login cookie in outgoing requests (bsc#1204303, CVE-2022-39201) * Security: Make proxy endpoints not leak sensitive HTTP headers diff --git a/grafana.spec b/grafana.spec index 3557a8e..738de84 100644 --- a/grafana.spec +++ b/grafana.spec @@ -22,7 +22,7 @@ %endif Name: grafana -Version: 8.5.14 +Version: 8.5.15 Release: 0 Summary: The open-source platform for monitoring and observability License: AGPL-3.0-only diff --git a/vendor.tar.gz b/vendor.tar.gz index 1a668d0..d4f8444 100644 --- a/vendor.tar.gz +++ b/vendor.tar.gz @@ -1,3 +1,3 @@ version https://git-lfs.github.com/spec/v1 -oid sha256:dc8e7e00005270ac05622f186e395b8d6e0bec2a698a5cd3dbc121b34f17e40d -size 19588498 +oid sha256:2c2877e029bff95ab8f00142f38a53f40d197ebc1e711747a70fc1af3f7d9a78 +size 19588389