Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2020:2676 - Security Advisory
Issued:
2020-06-23
Updated:
2020-06-23

RHSA-2020:2676 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: grafana security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for grafana is now available for Red Hat Enterprise Linux 8.1 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.

Security Fix(es):

  • grafana: SSRF incorrect access control vulnerability allows unauthenticated users to make grafana send HTTP requests to any URL (CVE-2020-13379)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.1 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.1 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.1 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.1 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1 x86_64

Fixes

  • BZ - 1843640 - CVE-2020-13379 grafana: SSRF incorrect access control vulnerability allows unauthenticated users to make grafana send HTTP requests to any URL

CVEs

  • CVE-2020-13379

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.1

SRPM
grafana-6.2.2-6.el8_1.src.rpm SHA-256: ed4c2ed69466299ec1ccb330aff0c187555925b43449201bd178ab1f9ac3f464
x86_64
grafana-6.2.2-6.el8_1.x86_64.rpm SHA-256: 4c91e47a545a54d444e34de695d874442ee3221a81ba1041d202e6f2f6bcea8b
grafana-azure-monitor-6.2.2-6.el8_1.x86_64.rpm SHA-256: 0f0d53152c8512d11ddd086344fccd5d0b30c6d868cad7f465bc585f8714690c
grafana-cloudwatch-6.2.2-6.el8_1.x86_64.rpm SHA-256: 9f9abacad04b624e682a030b177e055a9bd283b50bcbb380e44dcb3fd52bf9b6
grafana-debuginfo-6.2.2-6.el8_1.x86_64.rpm SHA-256: 04335e1a656e873a01e41e8e18bf3db0605e5c3996f7b7f25c9e67538ea1939e
grafana-elasticsearch-6.2.2-6.el8_1.x86_64.rpm SHA-256: 5543250153c2cbd0feb213c326016967733941a6aeb7b654250c937a6e72b040
grafana-graphite-6.2.2-6.el8_1.x86_64.rpm SHA-256: 0edac9c50e3fcec0f4de8b3e53eb9f5c8b7748c0412c284fae0ce013975f558d
grafana-influxdb-6.2.2-6.el8_1.x86_64.rpm SHA-256: a1fe1f4fe693ab7ce5fbb83f15174a985aa091dcc3c6470c816af935eefb536f
grafana-loki-6.2.2-6.el8_1.x86_64.rpm SHA-256: 2b318b53df06c39e5306819d6981de575627421c9232e0e7a5f0f35375c97b67
grafana-mssql-6.2.2-6.el8_1.x86_64.rpm SHA-256: 30c9d38e93810dfa906c13b7468f0dfde1ef9b013ac51944b9e7d631d21ec30e
grafana-mysql-6.2.2-6.el8_1.x86_64.rpm SHA-256: 50e642b9c5faf34db60aa55dfe0a518689eab9e2e90453771258fb71509c5e27
grafana-opentsdb-6.2.2-6.el8_1.x86_64.rpm SHA-256: 0aa201e4afa745282f4e199ac74dc1e960b45678f67fe71c004a2106f387d568
grafana-postgres-6.2.2-6.el8_1.x86_64.rpm SHA-256: 5f23bdf11045000c26d0b6e9fdf2a10b514119667b33f4b71e206607962f3efd
grafana-prometheus-6.2.2-6.el8_1.x86_64.rpm SHA-256: 49dd95da2afee5f4d4b3ff06d0dc8ca93e244c9e6de885b3caa0adfa5f00cda4
grafana-stackdriver-6.2.2-6.el8_1.x86_64.rpm SHA-256: f3350459da3bb08cc9fd62cdf764cbbeec564451dd6645fd2b12f7e629b46142

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.1

SRPM
grafana-6.2.2-6.el8_1.src.rpm SHA-256: ed4c2ed69466299ec1ccb330aff0c187555925b43449201bd178ab1f9ac3f464
s390x
grafana-6.2.2-6.el8_1.s390x.rpm SHA-256: 398a2987102d6d9b0e279406a382e23144db294e49d585bc53792354173e0f2b
grafana-azure-monitor-6.2.2-6.el8_1.s390x.rpm SHA-256: 4cf1d896a99d828d69bc168b4887710e80157d72cff94ed7c40483befdf76409
grafana-cloudwatch-6.2.2-6.el8_1.s390x.rpm SHA-256: 1ddad795159fa079350ef9ac098ad178812595f90fda8e2d368025e6c857dde4
grafana-debuginfo-6.2.2-6.el8_1.s390x.rpm SHA-256: 4df7c64b3c15ee585ae87bcc564712189fcb21c0d454fa75497eb0301a2f1aaa
grafana-elasticsearch-6.2.2-6.el8_1.s390x.rpm SHA-256: 580aa2605f742af924d203e7327755a9eab148c4ee44374b2d3232fcd1b60d4d
grafana-graphite-6.2.2-6.el8_1.s390x.rpm SHA-256: 71900fb74b97c2d09f6c60b62d4cd717e82376240779840fedaa3efe00d2da85
grafana-influxdb-6.2.2-6.el8_1.s390x.rpm SHA-256: f57e55dd9c9296ebf4651a421db62143cad4e2e681a4b79f725a64cb2a3f6fea
grafana-loki-6.2.2-6.el8_1.s390x.rpm SHA-256: de212dfc7e3dab23d22712ed5b07864b77555c4e54ff49877d8c41cce18868b0
grafana-mssql-6.2.2-6.el8_1.s390x.rpm SHA-256: bbb4bf73cf9fe51e442951b78e01be6a57ad411a598973dc49b7734052e8c620
grafana-mysql-6.2.2-6.el8_1.s390x.rpm SHA-256: 3ea60c59c18d505ad7f3e553fc796b3987e9a275b52a1160cc6740ef8cf0cc45
grafana-opentsdb-6.2.2-6.el8_1.s390x.rpm SHA-256: c8a8cf785444b78724ef330700e840f42fecb5a036c9be28fdee2dff5eac869a
grafana-postgres-6.2.2-6.el8_1.s390x.rpm SHA-256: 94ef6cb9dd93574adb50a541b01599b81b1b3fc58a02212dd732b1900f264308
grafana-prometheus-6.2.2-6.el8_1.s390x.rpm SHA-256: 6de3232a025d0096b9aa1813c2aa013595ea39c87cb7459d48a3179490cec283
grafana-stackdriver-6.2.2-6.el8_1.s390x.rpm SHA-256: 5a5c1ca9c51b20a3b3caa36a2e53f862f09891e02b6ab196ea5a29a1c045343d

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.1

SRPM
grafana-6.2.2-6.el8_1.src.rpm SHA-256: ed4c2ed69466299ec1ccb330aff0c187555925b43449201bd178ab1f9ac3f464
ppc64le
grafana-6.2.2-6.el8_1.ppc64le.rpm SHA-256: 08564d979f197cec6509d3382339eb8aa04b5ee9b377f35599f6bfbda48b64e8
grafana-azure-monitor-6.2.2-6.el8_1.ppc64le.rpm SHA-256: d36c7bae26c93a6e2189687156b2477358bede0f3c0e4770ead2d6781cbba5af
grafana-cloudwatch-6.2.2-6.el8_1.ppc64le.rpm SHA-256: 33e2158f6868f7ddc85df2015dbed541b837d06bf78db3ec14453992678efdeb
grafana-debuginfo-6.2.2-6.el8_1.ppc64le.rpm SHA-256: b84c049d7000d085d1dba95e19a058ecfc3deb5c66cf1b34b61b5b9c98af10b2
grafana-elasticsearch-6.2.2-6.el8_1.ppc64le.rpm SHA-256: 972712a78a7f151aaca9941d076ed2bac5518b9b070ccc727ebbba438fed430d
grafana-graphite-6.2.2-6.el8_1.ppc64le.rpm SHA-256: 3507b91a6a60b1f5e56a516fbda95d401c0df96958f3875824fb47530a9db4c8
grafana-influxdb-6.2.2-6.el8_1.ppc64le.rpm SHA-256: c7d58ca9d4021d564b5112b27b639a47818a5850e0c86c74d3fc8638d8396984
grafana-loki-6.2.2-6.el8_1.ppc64le.rpm SHA-256: 8c95d19134110a61f1e3b0838f8410dce1c05d08f7554680856dec3477644c93
grafana-mssql-6.2.2-6.el8_1.ppc64le.rpm SHA-256: c7ad4f344de3ba7d0fd7e586b9d980cc91473519e10ce0adaff827e64fa47533
grafana-mysql-6.2.2-6.el8_1.ppc64le.rpm SHA-256: c06dd52ca13d57dde0cbf10e9827daee39aa19ca98d3a6666beb52464ab40931
grafana-opentsdb-6.2.2-6.el8_1.ppc64le.rpm SHA-256: ae364a11acc84f26c44dac7489e920fcec02f7cfaf3ef1d174417e21e9ee0961
grafana-postgres-6.2.2-6.el8_1.ppc64le.rpm SHA-256: 25baa197e47296dc81ad9ede1ce045a0dd5bb90ab732f2683b197fa3fd836398
grafana-prometheus-6.2.2-6.el8_1.ppc64le.rpm SHA-256: 74cf95abf74fc55a97b0e09b19643864ca977c5db90ee028f06717217eb4906a
grafana-stackdriver-6.2.2-6.el8_1.ppc64le.rpm SHA-256: 2359e0730b4080bba7d70c1cdb2822f490f65220cac4e200f4cac728ab1331a9

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.1

SRPM
grafana-6.2.2-6.el8_1.src.rpm SHA-256: ed4c2ed69466299ec1ccb330aff0c187555925b43449201bd178ab1f9ac3f464
aarch64
grafana-6.2.2-6.el8_1.aarch64.rpm SHA-256: 657cb8e34dcf36453cb71eac860b6e7addacf9f49354363b31c58e5d987999d4
grafana-azure-monitor-6.2.2-6.el8_1.aarch64.rpm SHA-256: 0b6e2333d945fae499b83ccded1836300bbd171eab335f284c382fc408f7e871
grafana-cloudwatch-6.2.2-6.el8_1.aarch64.rpm SHA-256: 7abfde80326992d6360beb21e48fdfc1b150618e354ca72bbc4fcc21293f7fa3
grafana-debuginfo-6.2.2-6.el8_1.aarch64.rpm SHA-256: 89bf2b114bf1c0a7e7db5c39b2a76946ebdafffa1d00013e02c04a510063ec24
grafana-elasticsearch-6.2.2-6.el8_1.aarch64.rpm SHA-256: b8f7c910fdce31b2e887d312e573434fce1fa8331386b68dec4c4a1c28f21e6a
grafana-graphite-6.2.2-6.el8_1.aarch64.rpm SHA-256: bbcb768504b991e13be9fd398b0096fc00db2ccc3da1b8b269a6e7d838dcea5a
grafana-influxdb-6.2.2-6.el8_1.aarch64.rpm SHA-256: e243856aeff0b7e4ca9bafb55cecd94677bf9000be889a142d530ad7956f3ca2
grafana-loki-6.2.2-6.el8_1.aarch64.rpm SHA-256: d018a6861824c971c1ef304db8fbb1c42e883c77572a9ef4fc79d29f1afb1333
grafana-mssql-6.2.2-6.el8_1.aarch64.rpm SHA-256: 692d0d1d8880fc1641d57740544f69b5ad2695ae5df6f908a023fb4a337eec9b
grafana-mysql-6.2.2-6.el8_1.aarch64.rpm SHA-256: 595c35b8b432650bd356085b6b4366d681b8367eb10ee706d380463ce2710fdb
grafana-opentsdb-6.2.2-6.el8_1.aarch64.rpm SHA-256: 1b63c27e549ccaa8c9544eadb88c0bb826c42d025f2995e1184d75ccc671e4c6
grafana-postgres-6.2.2-6.el8_1.aarch64.rpm SHA-256: ad73a8fad15a75953d5a567efc7ea3cf5bfdefab7ef5c497a7426a0885d49033
grafana-prometheus-6.2.2-6.el8_1.aarch64.rpm SHA-256: 87bdc7f342ffe8b7f93f161a92ee2016831413ef9a127a62e4aadf7eed0552e1
grafana-stackdriver-6.2.2-6.el8_1.aarch64.rpm SHA-256: 1c8870a35913f3ce1ed239c2b5b81bfc9aa7a5cf9d3df3b984e6165455cfc882

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1

SRPM
grafana-6.2.2-6.el8_1.src.rpm SHA-256: ed4c2ed69466299ec1ccb330aff0c187555925b43449201bd178ab1f9ac3f464
ppc64le
grafana-6.2.2-6.el8_1.ppc64le.rpm SHA-256: 08564d979f197cec6509d3382339eb8aa04b5ee9b377f35599f6bfbda48b64e8
grafana-azure-monitor-6.2.2-6.el8_1.ppc64le.rpm SHA-256: d36c7bae26c93a6e2189687156b2477358bede0f3c0e4770ead2d6781cbba5af
grafana-cloudwatch-6.2.2-6.el8_1.ppc64le.rpm SHA-256: 33e2158f6868f7ddc85df2015dbed541b837d06bf78db3ec14453992678efdeb
grafana-debuginfo-6.2.2-6.el8_1.ppc64le.rpm SHA-256: b84c049d7000d085d1dba95e19a058ecfc3deb5c66cf1b34b61b5b9c98af10b2
grafana-elasticsearch-6.2.2-6.el8_1.ppc64le.rpm SHA-256: 972712a78a7f151aaca9941d076ed2bac5518b9b070ccc727ebbba438fed430d
grafana-graphite-6.2.2-6.el8_1.ppc64le.rpm SHA-256: 3507b91a6a60b1f5e56a516fbda95d401c0df96958f3875824fb47530a9db4c8
grafana-influxdb-6.2.2-6.el8_1.ppc64le.rpm SHA-256: c7d58ca9d4021d564b5112b27b639a47818a5850e0c86c74d3fc8638d8396984
grafana-loki-6.2.2-6.el8_1.ppc64le.rpm SHA-256: 8c95d19134110a61f1e3b0838f8410dce1c05d08f7554680856dec3477644c93
grafana-mssql-6.2.2-6.el8_1.ppc64le.rpm SHA-256: c7ad4f344de3ba7d0fd7e586b9d980cc91473519e10ce0adaff827e64fa47533
grafana-mysql-6.2.2-6.el8_1.ppc64le.rpm SHA-256: c06dd52ca13d57dde0cbf10e9827daee39aa19ca98d3a6666beb52464ab40931
grafana-opentsdb-6.2.2-6.el8_1.ppc64le.rpm SHA-256: ae364a11acc84f26c44dac7489e920fcec02f7cfaf3ef1d174417e21e9ee0961
grafana-postgres-6.2.2-6.el8_1.ppc64le.rpm SHA-256: 25baa197e47296dc81ad9ede1ce045a0dd5bb90ab732f2683b197fa3fd836398
grafana-prometheus-6.2.2-6.el8_1.ppc64le.rpm SHA-256: 74cf95abf74fc55a97b0e09b19643864ca977c5db90ee028f06717217eb4906a
grafana-stackdriver-6.2.2-6.el8_1.ppc64le.rpm SHA-256: 2359e0730b4080bba7d70c1cdb2822f490f65220cac4e200f4cac728ab1331a9

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1

SRPM
grafana-6.2.2-6.el8_1.src.rpm SHA-256: ed4c2ed69466299ec1ccb330aff0c187555925b43449201bd178ab1f9ac3f464
x86_64
grafana-6.2.2-6.el8_1.x86_64.rpm SHA-256: 4c91e47a545a54d444e34de695d874442ee3221a81ba1041d202e6f2f6bcea8b
grafana-azure-monitor-6.2.2-6.el8_1.x86_64.rpm SHA-256: 0f0d53152c8512d11ddd086344fccd5d0b30c6d868cad7f465bc585f8714690c
grafana-cloudwatch-6.2.2-6.el8_1.x86_64.rpm SHA-256: 9f9abacad04b624e682a030b177e055a9bd283b50bcbb380e44dcb3fd52bf9b6
grafana-debuginfo-6.2.2-6.el8_1.x86_64.rpm SHA-256: 04335e1a656e873a01e41e8e18bf3db0605e5c3996f7b7f25c9e67538ea1939e
grafana-elasticsearch-6.2.2-6.el8_1.x86_64.rpm SHA-256: 5543250153c2cbd0feb213c326016967733941a6aeb7b654250c937a6e72b040
grafana-graphite-6.2.2-6.el8_1.x86_64.rpm SHA-256: 0edac9c50e3fcec0f4de8b3e53eb9f5c8b7748c0412c284fae0ce013975f558d
grafana-influxdb-6.2.2-6.el8_1.x86_64.rpm SHA-256: a1fe1f4fe693ab7ce5fbb83f15174a985aa091dcc3c6470c816af935eefb536f
grafana-loki-6.2.2-6.el8_1.x86_64.rpm SHA-256: 2b318b53df06c39e5306819d6981de575627421c9232e0e7a5f0f35375c97b67
grafana-mssql-6.2.2-6.el8_1.x86_64.rpm SHA-256: 30c9d38e93810dfa906c13b7468f0dfde1ef9b013ac51944b9e7d631d21ec30e
grafana-mysql-6.2.2-6.el8_1.x86_64.rpm SHA-256: 50e642b9c5faf34db60aa55dfe0a518689eab9e2e90453771258fb71509c5e27
grafana-opentsdb-6.2.2-6.el8_1.x86_64.rpm SHA-256: 0aa201e4afa745282f4e199ac74dc1e960b45678f67fe71c004a2106f387d568
grafana-postgres-6.2.2-6.el8_1.x86_64.rpm SHA-256: 5f23bdf11045000c26d0b6e9fdf2a10b514119667b33f4b71e206607962f3efd
grafana-prometheus-6.2.2-6.el8_1.x86_64.rpm SHA-256: 49dd95da2afee5f4d4b3ff06d0dc8ca93e244c9e6de885b3caa0adfa5f00cda4
grafana-stackdriver-6.2.2-6.el8_1.x86_64.rpm SHA-256: f3350459da3bb08cc9fd62cdf764cbbeec564451dd6645fd2b12f7e629b46142

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility