Bug 231019 - www/grafana5: Update to 5.2.3, fixes LDAP & OAuth login vulnerability (CVE-2018-558213)
Summary: www/grafana5: Update to 5.2.3, fixes LDAP & OAuth login vulnerability (CVE-20...
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Only Me
Assignee: Steve Wills
URL: https://github.com/grafana/grafana/re...
Keywords:
Depends on:
Blocks:
 
Reported: 2018-08-30 13:09 UTC by Dmitri Goutnik
Modified: 2021-02-14 11:45 UTC (History)
4 users (show)

See Also:
bugzilla: maintainer-feedback? (swills)


Attachments
grafana5-5.2.3.patch (3.64 KB, patch)
2018-08-30 13:09 UTC, Dmitri Goutnik
dmgk: maintainer-approval?
Details | Diff
vuxml-grafana5.patch (1.85 KB, patch)
2018-08-30 13:10 UTC, Dmitri Goutnik
dmgk: maintainer-approval?
Details | Diff
plist patch (2.68 KB, patch)
2018-08-31 04:10 UTC, Nathan
no flags Details | Diff
plist fix (2.69 KB, patch)
2018-08-31 04:12 UTC, Nathan
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Dmitri Goutnik freebsd_committer freebsd_triage 2018-08-30 13:09:34 UTC
Created attachment 196704 [details]
grafana5-5.2.3.patch

- Update 5.2.2 -> 5.2.3
- Add VuXML entry

Changelog: https://github.com/grafana/grafana/releases/tag/v5.2.3

QA:
  poudriere testport: OK (112a, 104i)
Comment 1 Dmitri Goutnik freebsd_committer freebsd_triage 2018-08-30 13:10:20 UTC
Created attachment 196705 [details]
vuxml-grafana5.patch
Comment 2 Nathan 2018-08-31 04:04:34 UTC
I get:
Error: Orphaned: %%DATADIR%%/public/build/0.6aa12092d3333cb24394.js
Error: Orphaned: %%DATADIR%%/public/build/0.6aa12092d3333cb24394.js.map
Error: Orphaned: %%DATADIR%%/public/build/1.6aa12092d3333cb24394.js
Error: Orphaned: %%DATADIR%%/public/build/1.6aa12092d3333cb24394.js.map
Error: Orphaned: %%DATADIR%%/public/build/app.6aa12092d3333cb24394.js
Error: Orphaned: %%DATADIR%%/public/build/app.6aa12092d3333cb24394.js.map
Error: Orphaned: %%DATADIR%%/public/build/dark.6aa12092d3333cb24394.js
Error: Orphaned: %%DATADIR%%/public/build/dark.6aa12092d3333cb24394.js.map
Error: Orphaned: %%DATADIR%%/public/build/light.6aa12092d3333cb24394.js
Error: Orphaned: %%DATADIR%%/public/build/light.6aa12092d3333cb24394.js.map
Error: Orphaned: %%DATADIR%%/public/build/manifest.6aa12092d3333cb24394.js
Error: Orphaned: %%DATADIR%%/public/build/manifest.6aa12092d3333cb24394.js.map
Error: Orphaned: %%DATADIR%%/public/build/vendor.6aa12092d3333cb24394.js
Error: Orphaned: %%DATADIR%%/public/build/vendor.6aa12092d3333cb24394.js.map
===> Checking for items in pkg-plist which are not in STAGEDIR
Error: Missing: %%DATADIR%%/public/build/0.4f5454f867a0cc2fe8dd.js
Error: Missing: %%DATADIR%%/public/build/0.4f5454f867a0cc2fe8dd.js.map
Error: Missing: %%DATADIR%%/public/build/1.4f5454f867a0cc2fe8dd.js
Error: Missing: %%DATADIR%%/public/build/1.4f5454f867a0cc2fe8dd.js.map
Error: Missing: %%DATADIR%%/public/build/app.4f5454f867a0cc2fe8dd.js
Error: Missing: %%DATADIR%%/public/build/app.4f5454f867a0cc2fe8dd.js.map
Error: Missing: %%DATADIR%%/public/build/dark.4f5454f867a0cc2fe8dd.js
Error: Missing: %%DATADIR%%/public/build/dark.4f5454f867a0cc2fe8dd.js.map
Error: Missing: %%DATADIR%%/public/build/light.4f5454f867a0cc2fe8dd.js
Error: Missing: %%DATADIR%%/public/build/light.4f5454f867a0cc2fe8dd.js.map
Error: Missing: %%DATADIR%%/public/build/manifest.4f5454f867a0cc2fe8dd.js
Error: Missing: %%DATADIR%%/public/build/manifest.4f5454f867a0cc2fe8dd.js.map
Error: Missing: %%DATADIR%%/public/build/vendor.4f5454f867a0cc2fe8dd.js
Error: Missing: %%DATADIR%%/public/build/vendor.4f5454f867a0cc2fe8dd.js.map
===> Error: Plist issues found.
*** Error code 1
Comment 3 Nathan 2018-08-31 04:05:36 UTC
Will submit a patch to fix the plist
Comment 4 Nathan 2018-08-31 04:10:33 UTC
Created attachment 196731 [details]
plist patch
Comment 5 Nathan 2018-08-31 04:12:37 UTC
Created attachment 196732 [details]
plist fix
Comment 6 Nathan 2018-08-31 04:30:20 UTC
Comment on attachment 196732 [details]
plist fix

After updating, it makes etcdir.conf.sample for some reason
Comment 7 commit-hook freebsd_committer freebsd_triage 2018-08-31 23:48:41 UTC
A commit references this bug:

Author: swills
Date: Fri Aug 31 23:47:51 UTC 2018
New revision: 478626
URL: https://svnweb.freebsd.org/changeset/ports/478626

Log:
  Document grafana issues

  PR:		 231019
  PR:		 231020
  PR:		 231021
  PR:		 231022

Changes:
  head/security/vuxml/vuln.xml
Comment 8 commit-hook freebsd_committer freebsd_triage 2018-08-31 23:48:49 UTC
A commit references this bug:

Author: swills
Date: Fri Aug 31 23:48:16 UTC 2018
New revision: 478631
URL: https://svnweb.freebsd.org/changeset/ports/478631

Log:
  www/grafana5: Update to 5.2.3

  PR:		231019
  Submitted by:	Dmitri Goutnik <dg@syrec.org>
  Security:	1f8d5806-ac51-11e8-9cb6-10c37b4ac2ea

Changes:
  head/www/grafana5/Makefile
  head/www/grafana5/distinfo
  head/www/grafana5/pkg-plist
Comment 9 Steve Wills freebsd_committer freebsd_triage 2018-08-31 23:49:44 UTC
Committed, thanks!
Comment 10 Everett Masel 2019-12-28 16:24:02 UTC
MARKED AS SPAM
Comment 11 Slavynskas 2021-02-14 11:45:08 UTC
MARKED AS SPAM