Bug 264082 - www/grafana{7,8}: Update to 8.5.3 and 7.5.16 (Fixes security vulnerability)
Summary: www/grafana{7,8}: Update to 8.5.3 and 7.5.16 (Fixes security vulnerability)
Status: Closed Overcome By Events
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Many People
Assignee: freebsd-ports-bugs (Nobody)
URL: https://grafana.com/blog/2022/05/19/g...
Keywords: needs-patch, needs-qa, security
Depends on:
Blocks:
 
Reported: 2022-05-19 19:09 UTC by Xander
Modified: 2022-11-07 15:11 UTC (History)
3 users (show)

See Also:
bugzilla: maintainer-feedback? (robsonmantovani)
drtr0jan: maintainer-feedback+
koobs: merge-quarterly?


Attachments
Update to Grafana 7.5.16 (2.08 KB, patch)
2022-05-19 19:09 UTC, Xander
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Xander 2022-05-19 19:09:16 UTC
Created attachment 234037 [details]
Update to Grafana 7.5.16

Update to 7.5.16 with moderate severity security fix

See https://grafana.com/blog/2022/05/19/grafana-enterprise-8.5.3-and-7.5.16-released-with-moderate-severity-security-fix/

security/vuxml will most likely be taken care of by more experienced users for www/grafana8 . This is just the patch to update the grafana7 port.
Comment 1 Kubilay Kocak freebsd_committer freebsd_triage 2022-05-20 01:58:57 UTC
^Triage: Pending patch for www/grafana8 and vuxml entry
Comment 2 Boris Korzun 2022-05-20 08:22:53 UTC
(In reply to Kubilay Kocak from comment #1)

Grafana OSS are not impacted by this vulnerability. The bug is only for Grafana Enterprise (there isn't in the ports tree).
Comment 3 Xander 2022-05-20 11:25:13 UTC
Grafana OSS indeed isn't impacted according to the blog. Grafana did however release new OSS versions 7.5.16 and 8.5.3 marked with "Security: Fixes CVE-2022-29170". See https://github.com/grafana/grafana/releases . That was my trigger to err on the safe side and provide a patch to keep track of the upstream OSS version.
Comment 4 Kubilay Kocak freebsd_committer freebsd_triage 2022-05-25 01:03:59 UTC
(In reply to Xander from comment #3)
(In reply to Boris Korzun from comment #2)

Thank you for the detail, so to be explicit and clarify:

- The OSS versions did not receive any security related changes to their codebases?
- The inclusion of "Fixes CVE-2022-29170" in the OSS version release notes is incorrect?

In particular, can we point to any commit logs and/or issues for CVE-2022-29170 so we have details of the branches they were applied to, or the absence of said merges to OSS branches?
Comment 5 Boris Korzun 2022-05-25 08:30:38 UTC
(In reply to Kubilay Kocak from comment #4)

- The OSS versions did not receive any security related changes to it. But codebase is common for OSS and Enterprise.
- The inclusion of "Fixes CVE-2022-29170" in the codebase release notes is correct.

I think, it isn't needed to commit new version to www/grafana8.
Comment 6 Xander 2022-11-07 15:11:55 UTC
Since www/grafana7 has been expired this ticket can be closed