diff --git a/_service b/_service index 5f8aa2e..7d1b402 100644 --- a/_service +++ b/_service @@ -5,7 +5,7 @@ .git @PARENT_TAG@ v(.*) - v8.5.13 + v8.5.14 enable diff --git a/_servicedata b/_servicedata index 1f13113..a809f9c 100644 --- a/_servicedata +++ b/_servicedata @@ -1,6 +1,6 @@ https://github.com/grafana/grafana - 38d274060d2dd6c4240edfdcc30d122e8120545d + 5bc88988a5a25c23452249315e8789ef059a2a3d \ No newline at end of file diff --git a/grafana-8.5.13.tar.gz b/grafana-8.5.13.tar.gz deleted file mode 100644 index fe7779f..0000000 --- a/grafana-8.5.13.tar.gz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:0ed3ae71c9cc0d552709d1943e98ee2c7d46c39034f3016e2fb4e98ed556c234 -size 51533917 diff --git a/grafana-8.5.14.tar.gz b/grafana-8.5.14.tar.gz new file mode 100644 index 0000000..66cb3db --- /dev/null +++ b/grafana-8.5.14.tar.gz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:a3a0e0161d454cb2585f0d5ebc58ada4c93420ea1c5bd6db5a1a42d0e93b9b8b +size 51535752 diff --git a/grafana.changes b/grafana.changes index 128003b..296e7f3 100644 --- a/grafana.changes +++ b/grafana.changes @@ -1,3 +1,15 @@ +------------------------------------------------------------------- +Fri Nov 11 09:06:30 UTC 2022 - witold.bedyk@suse.com + +- Update to version 8.5.14 (jsc#PED-2617): + * Security: Fix do not forward login cookie in outgoing requests + (bsc#1204303, CVE-2022-39201) + * Security: Make proxy endpoints not leak sensitive HTTP headers + (bsc#1204305, CVE-2022-31130) + * Security: Fix plugin signature bypass (bsc#1204302, CVE-2022-31123) + * Security: Fix blocknig other users from signing in (bsc#1204304, + CVE-2022-39229) + ------------------------------------------------------------------- Wed Sep 21 11:37:55 UTC 2022 - witold.bedyk@suse.com diff --git a/grafana.spec b/grafana.spec index f5e275d..3557a8e 100644 --- a/grafana.spec +++ b/grafana.spec @@ -22,7 +22,7 @@ %endif Name: grafana -Version: 8.5.13 +Version: 8.5.14 Release: 0 Summary: The open-source platform for monitoring and observability License: AGPL-3.0-only diff --git a/vendor.tar.gz b/vendor.tar.gz index 0b6b27f..1a668d0 100644 --- a/vendor.tar.gz +++ b/vendor.tar.gz @@ -1,3 +1,3 @@ version https://git-lfs.github.com/spec/v1 -oid sha256:72d3f2660f4a8183cb4328735bffb91df16b1cc3c1d022cd4631f0dc4f87a019 -size 19588431 +oid sha256:dc8e7e00005270ac05622f186e395b8d6e0bec2a698a5cd3dbc121b34f17e40d +size 19588498