Bug 261892 - www/grafana[678]: Update to latest versions (8.3.5, 7.?.?, 6.?.?) fixing security vulnerabilities
Summary: www/grafana[678]: Update to latest versions (8.3.5, 7.?.?, 6.?.?) fixing secu...
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Many People
Assignee: Thomas Zander
URL: https://grafana.com/blog/2022/02/08/g...
Keywords: needs-patch, needs-qa, security
Depends on:
Blocks:
 
Reported: 2022-02-11 23:04 UTC by Boris Korzun
Modified: 2022-04-04 06:58 UTC (History)
6 users (show)

See Also:
drtr0jan: maintainer-feedback+
riggs: maintainer-feedback-
riggs: maintainer-feedback-
riggs: merge-quarterly+


Attachments
grafana8.diff (2.05 KB, patch)
2022-02-11 23:04 UTC, Boris Korzun
drtr0jan: maintainer-approval+
Details | Diff
vuxml.diff (5.93 KB, patch)
2022-02-11 23:05 UTC, Boris Korzun
drtr0jan: maintainer-approval?
Details | Diff
grafana8.diff (10.75 KB, patch)
2022-02-16 11:20 UTC, Boris Korzun
drtr0jan: maintainer-approval+
Details | Diff
Update to Grafana 7.5.15 (2.42 KB, patch)
2022-03-31 19:36 UTC, Xander
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Boris Korzun 2022-02-11 23:04:47 UTC
Created attachment 231763 [details]
grafana8.diff

Update to 8.3.5

Security: Fixes CVE-2022-21702, CVE-2022-21703 and CVE-2022-21713.
Comment 1 Boris Korzun 2022-02-11 23:05:21 UTC
Created attachment 231764 [details]
vuxml.diff
Comment 2 Kubilay Kocak freebsd_committer freebsd_triage 2022-02-12 00:30:28 UTC
Thank you for the report and patch Boris. Are grafana 7 and 6 also affected?
Comment 3 Boris Korzun 2022-02-12 09:24:00 UTC
(In reply to Kubilay Kocak from comment #2)

Yep, Grafana 6 and 7 are also affected by the vulnerabilities.
Comment 4 Kubilay Kocak freebsd_committer freebsd_triage 2022-02-13 21:57:05 UTC
(In reply to Boris Korzun from comment #3)

Thank you. Since updates for those ports have not been created, we'll have this track and cover all. Could you please list, for each grafana port (except 8)

- The vulnerable version(s) string to facilitate vuxml entries
- The (minimum) fixed version
- Links to major version specific announcements and changelogs

If you can update to vuxml attachment to cover all major versions, that would be great.
Comment 5 Kubilay Kocak freebsd_committer freebsd_triage 2022-02-13 21:59:16 UTC
^Triage: Request feedback and update patches for grafana7 and grafana6 respectively
Comment 6 Boris Korzun 2022-02-13 22:20:01 UTC
(In reply to Kubilay Kocak from comment #4)

The vuxml attachment contains strings for grafana 7 and grafana 6 yet.

Grafana 7 fixed version (7.5.15) release notes - https://github.com/grafana/grafana/releases/tag/v7.5.15

Grafana 6 is't supported yet. I've created a bug #261560 for set it as deprecated.
Comment 7 Boris Korzun 2022-02-16 11:20:13 UTC
Created attachment 231862 [details]
grafana8.diff

Update to 8.3.6

Release notes: https://github.com/grafana/grafana/releases/tag/v8.3.6
Comment 8 Boris Korzun 2022-02-25 05:40:02 UTC
Ping.
Comment 9 commit-hook freebsd_committer freebsd_triage 2022-02-26 13:13:08 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=83a1ccc5f2868261bdd465fedd9d13e3ada2efdb

commit 83a1ccc5f2868261bdd465fedd9d13e3ada2efdb
Author:     Boris Korzun <drtr0jan@yandex.ru>
AuthorDate: 2022-02-26 13:10:11 +0000
Commit:     Thomas Zander <riggs@FreeBSD.org>
CommitDate: 2022-02-26 13:12:05 +0000

    www/grafana8: Update to upstream version 8.3.6

    PR:             261892
    MFH:            2022Q1
    Security:       CVE-2022-21702
                    CVE-2022-21703
                    CVE-2022-21713

 www/grafana8/Makefile         |  6 +++---
 www/grafana8/Makefile.modules |  4 ++--
 www/grafana8/distinfo         | 18 +++++++++---------
 www/grafana8/pkg-plist        | 18 +++++++++++-------
 4 files changed, 25 insertions(+), 21 deletions(-)
Comment 10 commit-hook freebsd_committer freebsd_triage 2022-02-26 14:27:23 UTC
A commit in branch 2022Q1 references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=6cad1d287bd2d3bdb5d1a0f9688096ee2c08ad11

commit 6cad1d287bd2d3bdb5d1a0f9688096ee2c08ad11
Author:     Boris Korzun <drtr0jan@yandex.ru>
AuthorDate: 2022-02-26 13:10:11 +0000
Commit:     Thomas Zander <riggs@FreeBSD.org>
CommitDate: 2022-02-26 14:02:39 +0000

    www/grafana8: Update to upstream version 8.3.6

    PR:             261892
    MFH:            2022Q1
    Security:       CVE-2022-21702
                    CVE-2022-21703
                    CVE-2022-21713
    (cherry picked from commit 83a1ccc5f2868261bdd465fedd9d13e3ada2efdb)

 www/grafana8/Makefile         |  6 +++---
 www/grafana8/Makefile.modules |  4 ++--
 www/grafana8/distinfo         | 18 +++++++++---------
 www/grafana8/pkg-plist        | 18 +++++++++++-------
 4 files changed, 25 insertions(+), 21 deletions(-)
Comment 11 commit-hook freebsd_committer freebsd_triage 2022-02-26 15:01:30 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=580776c6bd96e2b9de3e34a8c8c8b395b70aed69

commit 580776c6bd96e2b9de3e34a8c8c8b395b70aed69
Author:     Thomas Zander <riggs@FreeBSD.org>
AuthorDate: 2022-02-26 14:58:47 +0000
Commit:     Thomas Zander <riggs@FreeBSD.org>
CommitDate: 2022-02-26 14:58:47 +0000

    security/vuxml: Document grafana vulnerabilities

    PR:             261892
    Reported by:    Boris Korzun <drtr0jan@yandex.ru>
    Security:       CVE-2022-21702
                    CVE-2022-21703
                    CVE-2022-21713

 security/vuxml/vuln-2022.xml | 108 +++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 108 insertions(+)
Comment 12 Thomas Zander freebsd_committer freebsd_triage 2022-02-26 15:19:39 UTC
Hey robsonmantovani@gmail.com , can you prepare a patch for grafana7?
Comment 13 Xander 2022-03-31 19:36:03 UTC
Created attachment 232849 [details]
Update to Grafana 7.5.15

This patch will update to the latest upstream grafana7 release
Comment 14 commit-hook freebsd_committer freebsd_triage 2022-04-04 05:43:56 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=fd6096788e23395815509c76a7cdc2198ce6d5ce

commit fd6096788e23395815509c76a7cdc2198ce6d5ce
Author:     Thomas Zander <riggs@FreeBSD.org>
AuthorDate: 2022-04-04 05:39:38 +0000
Commit:     Thomas Zander <riggs@FreeBSD.org>
CommitDate: 2022-04-04 05:43:43 +0000

    www/grafana7: Update to upstream version 7.5.15

    PR:             261892
    Approved by:    Maintainer timeout
    MFH:            2022Q2
    Security:       CVE-2022-21702
                    CVE-2022-21703
                    CVE-2022-21713

 www/grafana7/Makefile |  7 +++----
 www/grafana7/distinfo | 10 +++++-----
 2 files changed, 8 insertions(+), 9 deletions(-)
Comment 15 commit-hook freebsd_committer freebsd_triage 2022-04-04 06:55:07 UTC
A commit in branch 2022Q2 references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=1dc12b72d5af395acf86652ceb506472657a3803

commit 1dc12b72d5af395acf86652ceb506472657a3803
Author:     Thomas Zander <riggs@FreeBSD.org>
AuthorDate: 2022-04-04 05:39:38 +0000
Commit:     Thomas Zander <riggs@FreeBSD.org>
CommitDate: 2022-04-04 05:44:23 +0000

    www/grafana7: Update to upstream version 7.5.15

    PR:             261892
    Approved by:    Maintainer timeout
    MFH:            2022Q2
    Security:       CVE-2022-21702
                    CVE-2022-21703
                    CVE-2022-21713

    (cherry picked from commit fd6096788e23395815509c76a7cdc2198ce6d5ce)

 www/grafana7/Makefile |  7 +++----
 www/grafana7/distinfo | 10 +++++-----
 2 files changed, 8 insertions(+), 9 deletions(-)
Comment 16 Thomas Zander freebsd_committer freebsd_triage 2022-04-04 06:58:01 UTC
Summary:
- grafana8 updates smooth.
- Feedback timeout for grafana{6|7} maintainers.
- grafana6 removed from main and 2022Q2.
- grafana7 patch provided by Xander (thanks!) and committed to main and 2022Q2.