Bug 272161 - www/grafana{8,9}: Update to 8.5.27 and 9.5.5 (Fixes critical security vulnerability)
Summary: www/grafana{8,9}: Update to 8.5.27 and 9.5.5 (Fixes critical security vulnera...
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Some People
Assignee: Nuno Teixeira
URL: https://grafana.com/blog/2023/06/22/g...
Keywords: security
Depends on:
Blocks:
 
Reported: 2023-06-23 10:42 UTC by Boris Korzun
Modified: 2023-06-25 08:35 UTC (History)
3 users (show)

See Also:
eduardo: merge-quarterly+


Attachments
grafana8.patch (2.21 KB, patch)
2023-06-23 10:42 UTC, Boris Korzun
drtr0jan: maintainer-approval+
Details | Diff
grafana9.patch (5.83 KB, patch)
2023-06-23 10:43 UTC, Boris Korzun
drtr0jan: maintainer-approval+
Details | Diff
vuxml.patch (2.12 KB, patch)
2023-06-23 10:45 UTC, Boris Korzun
eduardo: maintainer-approval+
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Boris Korzun 2023-06-23 10:42:03 UTC
Created attachment 242951 [details]
grafana8.patch

Update to 8.5.27.

Also set as deprecated after Grafana 10 released.
Comment 1 Boris Korzun 2023-06-23 10:43:01 UTC
Created attachment 242952 [details]
grafana9.patch

Update to 9.5.5
Comment 2 Boris Korzun 2023-06-23 10:45:15 UTC
Created attachment 242953 [details]
vuxml.patch

vuxml:
* CVE-2023-3128 - Account takeover / authentication bypass ( https://grafana.com/security/security-advisories/cve-2023-3128 )
Comment 3 commit-hook freebsd_committer freebsd_triage 2023-06-25 07:24:45 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=d86981321af78b575014891963f626fdca082ebf

commit d86981321af78b575014891963f626fdca082ebf
Author:     Boris Korzun <drtr0jan@yandex.ru>
AuthorDate: 2023-06-25 07:15:16 +0000
Commit:     Nuno Teixeira <eduardo@FreeBSD.org>
CommitDate: 2023-06-25 07:23:15 +0000

    www/grafana9: Update to 9.5.5

    ChangeLog:
    https://grafana.com/blog/2023/06/22/grafana-security-release-for-cve-2023-3128/

    PR:             272161
    MFH:            2023Q2
    Security:       fdbe9aec-118b-11ee-908a-6c3be5272acd

 www/grafana9/Makefile  |  4 ++--
 www/grafana9/distinfo  | 14 +++++++-------
 www/grafana9/pkg-plist | 22 ++++++++++++----------
 3 files changed, 21 insertions(+), 19 deletions(-)
Comment 4 commit-hook freebsd_committer freebsd_triage 2023-06-25 07:24:46 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=60127f6f4070d26b04328caf56ace7f0f2ca82a9

commit 60127f6f4070d26b04328caf56ace7f0f2ca82a9
Author:     Boris Korzun <drtr0jan@yandex.ru>
AuthorDate: 2023-06-24 22:52:55 +0000
Commit:     Nuno Teixeira <eduardo@FreeBSD.org>
CommitDate: 2023-06-25 07:23:15 +0000

    security/vuxml: Add www/grafana{8,9} vulnerabilities

    * CVE-2023-3128 - Account takeover / authentication bypass
    ( https://grafana.com/security/security-advisories/cve-2023-3128 )

    PR:             272161

 security/vuxml/vuln/2023.xml | 51 ++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 51 insertions(+)
Comment 5 commit-hook freebsd_committer freebsd_triage 2023-06-25 07:24:47 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=86d7d344b5e08dc28360f56dbce86354bcbfac82

commit 86d7d344b5e08dc28360f56dbce86354bcbfac82
Author:     Boris Korzun <drtr0jan@yandex.ru>
AuthorDate: 2023-06-25 07:20:20 +0000
Commit:     Nuno Teixeira <eduardo@FreeBSD.org>
CommitDate: 2023-06-25 07:23:16 +0000

    www/grafana8: Update to 8.5.27

     - Set as deprecated after Grafana 10 released.

    ChangeLog:
    https://grafana.com/blog/2023/06/22/grafana-security-release-for-cve-2023-3128/

    PR:             272161
    MFH:            2023Q2
    Security:       fdbe9aec-118b-11ee-908a-6c3be5272acd

 www/grafana8/Makefile |  7 +++++--
 www/grafana8/distinfo | 10 +++++-----
 2 files changed, 10 insertions(+), 7 deletions(-)
Comment 6 commit-hook freebsd_committer freebsd_triage 2023-06-25 08:34:00 UTC
A commit in branch 2023Q2 references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=ef95161b3d1eaf5745e4c6400beec8dd71b06c40

commit ef95161b3d1eaf5745e4c6400beec8dd71b06c40
Author:     Boris Korzun <drtr0jan@yandex.ru>
AuthorDate: 2023-06-25 07:15:16 +0000
Commit:     Nuno Teixeira <eduardo@FreeBSD.org>
CommitDate: 2023-06-25 07:26:33 +0000

    www/grafana9: Update to 9.5.5

    ChangeLog:
    https://grafana.com/blog/2023/06/22/grafana-security-release-for-cve-2023-3128/

    PR:             272161
    MFH:            2023Q2
    Security:       fdbe9aec-118b-11ee-908a-6c3be5272acd
    (cherry picked from commit d86981321af78b575014891963f626fdca082ebf)

 www/grafana9/Makefile  |  4 ++--
 www/grafana9/distinfo  | 14 +++++++-------
 www/grafana9/pkg-plist | 22 ++++++++++++----------
 3 files changed, 21 insertions(+), 19 deletions(-)
Comment 7 commit-hook freebsd_committer freebsd_triage 2023-06-25 08:34:01 UTC
A commit in branch 2023Q2 references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=422a0baba67fbed00c2f10941056f6c10253f9d2

commit 422a0baba67fbed00c2f10941056f6c10253f9d2
Author:     Boris Korzun <drtr0jan@yandex.ru>
AuthorDate: 2023-06-25 07:20:20 +0000
Commit:     Nuno Teixeira <eduardo@FreeBSD.org>
CommitDate: 2023-06-25 07:25:01 +0000

    www/grafana8: Update to 8.5.27

     - Set as deprecated after Grafana 10 released.

    ChangeLog:
    https://grafana.com/blog/2023/06/22/grafana-security-release-for-cve-2023-3128/

    PR:             272161
    MFH:            2023Q2
    Security:       fdbe9aec-118b-11ee-908a-6c3be5272acd
    (cherry picked from commit 86d7d344b5e08dc28360f56dbce86354bcbfac82)

 www/grafana8/Makefile |  7 +++++--
 www/grafana8/distinfo | 10 +++++-----
 2 files changed, 10 insertions(+), 7 deletions(-)
Comment 8 Nuno Teixeira freebsd_committer freebsd_triage 2023-06-25 08:35:40 UTC
Committed, thanks!