-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: grafana security and bug fix update
Advisory ID:       RHSA-2019:0019-01
Product:           Red Hat Ceph Storage
Advisory URL:      https://access.redhat.com/errata/RHSA-2019:0019
Issue date:        2019-01-03
CVE Names:         CVE-2018-15727 
====================================================================
1. Summary:

The updated grafana package is now available for Red Hat Ceph Storage 3.2.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Ceph Storage 3.2 Tools - x86_64

3. Description:

The grafana package provides the Grafana metrics dashboard and graph
editor.

Security Fix(es):

* grafana: authentication bypass knowing only a username of an LDAP or
OAuth user (CVE-2018-15727)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.

Bug Fix(es):

* The grafana package has been upgraded to upstream version 5.2.4., which
includes a number of bug fixes (BZ#1647494)

* Shrinking the cluster size no longer causes the Red Hat Ceph Storage
Dashboard to display the error message Templating init failed (BZ#1653273)

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1624088 - CVE-2018-15727 grafana: authentication bypass  knowing only a username of an LDAP or OAuth user
1633825 - Add ceph FS support in ceph metrics
1647494 - Update grafana to latest for security fixes
1647496 - Remove golang dependency from grafana
1652427 - [ceph-metrics]Change password is not working
1653273 - Metrics dashboard is throwing "Templating init failed" error after rerunning metrics playbook

6. Package List:

Red Hat Ceph Storage 3.2 Tools:

Source:
grafana-5.2.4-1.el7cp.src.rpm

x86_64:
grafana-5.2.4-1.el7cp.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2018-15727
https://access.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2019 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXC5KJdzjgjWX9erEAQgxMxAAiFfYtrxvJlnPJiTV9TeKNe+Mf20OVHJJ
4v8RwDawhocT+U6qmvAyATlLIi38mrBT2JX9K+RQVXOCR+lr/0umkyU9qVizSoCQ
9zlKBfdCdw0Ot4zcRYO+pHw9eOjL1JzsxGBAPuU6i9qkN0SBi/BkxT/tXJ0vlqjR
N9p6nYfyoA7UDmfLtppGfqu87lZkLXYKICf+2By6XJ48a510oOTRTxvxAQV+2cGn
3oXZroZk+MEgNFggz4Vq9tA2evpNzmOqicub2LBnruD2BKlp14kAbsHWtfVCbNXp
GeWwsFGfVleY4ww3v8pW357lWDVsMMtyHDgGxFQAv1e+aHE3aCDj3z+R4iwUczeM
DohgkyMz5oyfiIJCigV9mzyYAlPN/JCJJyxJlp0/2hOR2lyWeeoGych5Ih3NnBkV
tlS5RdHNQfNKgoYX+xNoyT//A4SctpcknLZckN8TgNCAk4sjoN9b2jyGObB1xXaZ
O5m3dF7zgWZO92T4SchklueiVk1Wj1GcMxb9dTApQrTBLPVwkOJpOoRD2goXkAhE
S3SYYRU1KdJjO6lpG55oR52P42v7HG8b26KNwiqBBMtTaMepjQ8LUcG8d56e8yV2
nQhqlxDMuBgEacr5awuXy4iHmlTyNx06CqlHMLpBoz/UCqULK1A9F8HeBr/Orpm6
tvGLVZbg0yo=hmTs
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2019-0019:01 Moderate: grafana security and bug fix update

The updated grafana package is now available for Red Hat Ceph Storage 3.2

Summary

The grafana package provides the Grafana metrics dashboard and graph editor.
Security Fix(es):
* grafana: authentication bypass knowing only a username of an LDAP or OAuth user (CVE-2018-15727)
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* The grafana package has been upgraded to upstream version 5.2.4., which includes a number of bug fixes (BZ#1647494)
* Shrinking the cluster size no longer causes the Red Hat Ceph Storage Dashboard to display the error message Templating init failed (BZ#1653273)



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2018-15727 https://access.redhat.com/security/updates/classification/#moderate

Package List

Red Hat Ceph Storage 3.2 Tools:
Source: grafana-5.2.4-1.el7cp.src.rpm
x86_64: grafana-5.2.4-1.el7cp.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2019:0019-01
Product: Red Hat Ceph Storage
Advisory URL: https://access.redhat.com/errata/RHSA-2019:0019
Issued Date: : 2019-01-03
CVE Names: CVE-2018-15727

Topic

The updated grafana package is now available for Red Hat Ceph Storage 3.2.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat Ceph Storage 3.2 Tools - x86_64


Bugs Fixed

1624088 - CVE-2018-15727 grafana: authentication bypass knowing only a username of an LDAP or OAuth user

1633825 - Add ceph FS support in ceph metrics

1647494 - Update grafana to latest for security fixes

1647496 - Remove golang dependency from grafana

1652427 - [ceph-metrics]Change password is not working

1653273 - Metrics dashboard is throwing "Templating init failed" error after rerunning metrics playbook


Related News