Bug 270562 - www/grafana{8,9}: Update to 8.5.22 and 9.4.7 (Fixes security vulnerability)
Summary: www/grafana{8,9}: Update to 8.5.22 and 9.4.7 (Fixes security vulnerability)
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Some People
Assignee: freebsd-ports-bugs (Nobody)
URL: https://grafana.com/blog/2023/03/22/g...
Keywords: security
Depends on:
Blocks:
 
Reported: 2023-03-31 13:37 UTC by Boris Korzun
Modified: 2023-04-01 07:22 UTC (History)
2 users (show)

See Also:
drtr0jan: merge-quarterly?


Attachments
grafana8.diff (3.06 KB, patch)
2023-03-31 13:37 UTC, Boris Korzun
drtr0jan: maintainer-approval+
Details | Diff
grafana9.diff (29.63 KB, patch)
2023-03-31 13:38 UTC, Boris Korzun
drtr0jan: maintainer-approval+
Details | Diff
vuxml.diff (2.43 KB, patch)
2023-03-31 13:40 UTC, Boris Korzun
drtr0jan: maintainer-approval? (ports-secteam)
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Boris Korzun 2023-03-31 13:37:36 UTC
Created attachment 241229 [details]
grafana8.diff

Update to 8.5.22
Comment 1 Boris Korzun 2023-03-31 13:38:12 UTC
Created attachment 241230 [details]
grafana9.diff

Update to 9.4.7
Comment 2 Boris Korzun 2023-03-31 13:40:05 UTC
Created attachment 241231 [details]
vuxml.diff

vuxml: CVE-2023-1410 - Stored XSS in Graphite FunctionDescription tooltip
Comment 3 commit-hook freebsd_committer freebsd_triage 2023-04-01 07:13:38 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=3a01bbfd5a833521c665aca61d388137b74c5237

commit 3a01bbfd5a833521c665aca61d388137b74c5237
Author:     Matthew Seaman <matthew@FreeBSD.org>
AuthorDate: 2023-04-01 07:11:55 +0000
Commit:     Matthew Seaman <matthew@FreeBSD.org>
CommitDate: 2023-04-01 07:12:54 +0000

    www/grafana9: security update to 9.4.7

    https://grafana.com/blog/2023/03/22/grafana-security-release-new-versions-with-security-fixes-for-cve-2023-1410/

    PR:             270562
    Approved by:    Boris Korzun (maintainer)
    MFH:            2023Q2
    Security:       955eb3cc-ce0b-11ed-825f-6c3be5272acd

 www/grafana9/Makefile  |   5 +-
 www/grafana9/distinfo  |  14 ++--
 www/grafana9/pkg-plist | 182 +++++++++++++++++++++++++------------------------
 3 files changed, 102 insertions(+), 99 deletions(-)
Comment 4 commit-hook freebsd_committer freebsd_triage 2023-04-01 07:13:39 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=d83c498e9b35b08257651d5a841993dc23c3abda

commit d83c498e9b35b08257651d5a841993dc23c3abda
Author:     Matthew Seaman <matthew@FreeBSD.org>
AuthorDate: 2023-04-01 07:05:52 +0000
Commit:     Matthew Seaman <matthew@FreeBSD.org>
CommitDate: 2023-04-01 07:12:54 +0000

    www/grafana8: security update to 8.5.22

    https://grafana.com/blog/2023/03/22/grafana-security-release-new-versions-with-security-fixes-for-cve-2023-1410/

    PR:             270562
    Approved by:    Boris Korzun (maintainer)
    MFH:            2023Q2
    Security:       955eb3cc-ce0b-11ed-825f-6c3be5272acd

 www/grafana8/Makefile  |  7 +++----
 www/grafana8/distinfo  | 10 +++++-----
 www/grafana8/pkg-plist |  3 ---
 3 files changed, 8 insertions(+), 12 deletions(-)
Comment 5 commit-hook freebsd_committer freebsd_triage 2023-04-01 07:13:40 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=686ee0f81612ea3ff229b5273314ef1b961cd8c7

commit 686ee0f81612ea3ff229b5273314ef1b961cd8c7
Author:     Matthew Seaman <matthew@FreeBSD.org>
AuthorDate: 2023-04-01 07:02:53 +0000
Commit:     Matthew Seaman <matthew@FreeBSD.org>
CommitDate: 2023-04-01 07:12:53 +0000

    security/vuxml: document grafana vulnerabilities

    CVE-2023-1410

    PR:             270562
    Reported by:    Boris Korzun

 security/vuxml/vuln/2023.xml | 51 ++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 51 insertions(+)
Comment 6 commit-hook freebsd_committer freebsd_triage 2023-04-01 07:21:45 UTC
A commit in branch 2023Q2 references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=c0eadf3e6a75c23a9238847a11e2a61f784456eb

commit c0eadf3e6a75c23a9238847a11e2a61f784456eb
Author:     Matthew Seaman <matthew@FreeBSD.org>
AuthorDate: 2023-04-01 07:05:52 +0000
Commit:     Matthew Seaman <matthew@FreeBSD.org>
CommitDate: 2023-04-01 07:20:38 +0000

    www/grafana8: security update to 8.5.22

    https://grafana.com/blog/2023/03/22/grafana-security-release-new-versions-with-security-fixes-for-cve-2023-1410/

    PR:             270562
    Approved by:    Boris Korzun (maintainer)
    MFH:            2023Q2
    Security:       955eb3cc-ce0b-11ed-825f-6c3be5272acd

    (cherry picked from commit d83c498e9b35b08257651d5a841993dc23c3abda)

 www/grafana8/Makefile  |  7 +++----
 www/grafana8/distinfo  | 10 +++++-----
 www/grafana8/pkg-plist |  3 ---
 3 files changed, 8 insertions(+), 12 deletions(-)
Comment 7 commit-hook freebsd_committer freebsd_triage 2023-04-01 07:21:46 UTC
A commit in branch 2023Q2 references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=22103045144ebe561578e12230d009e8d783d2f9

commit 22103045144ebe561578e12230d009e8d783d2f9
Author:     Matthew Seaman <matthew@FreeBSD.org>
AuthorDate: 2023-04-01 07:11:55 +0000
Commit:     Matthew Seaman <matthew@FreeBSD.org>
CommitDate: 2023-04-01 07:20:38 +0000

    www/grafana9: security update to 9.4.7

    https://grafana.com/blog/2023/03/22/grafana-security-release-new-versions-with-security-fixes-for-cve-2023-1410/

    PR:             270562
    Approved by:    Boris Korzun (maintainer)
    MFH:            2023Q2
    Security:       955eb3cc-ce0b-11ed-825f-6c3be5272acd

    (cherry picked from commit 3a01bbfd5a833521c665aca61d388137b74c5237)

 www/grafana9/Makefile  |   5 +-
 www/grafana9/distinfo  |  14 ++--
 www/grafana9/pkg-plist | 182 +++++++++++++++++++++++++------------------------
 3 files changed, 102 insertions(+), 99 deletions(-)
Comment 8 Matthew Seaman freebsd_committer freebsd_triage 2023-04-01 07:22:20 UTC
Committed, thanks!