RHSA-2025:3344HighCVSS 8.1
Red Hat Security Advisory: grafana security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-21613 — go-git: argument injection via the URL field CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
🎯 Affected products18
- Red Hat Enterprise Linux AppStream (v. 9)
- grafana-0:10.2.6-9.el9_5.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- grafana-0:10.2.6-9.el9_5.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- grafana-0:10.2.6-9.el9_5.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- grafana-0:10.2.6-9.el9_5.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
- grafana-0:10.2.6-9.el9_5.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- grafana-debuginfo-0:10.2.6-9.el9_5.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- grafana-debuginfo-0:10.2.6-9.el9_5.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- grafana-debuginfo-0:10.2.6-9.el9_5.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- grafana-debuginfo-0:10.2.6-9.el9_5.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- grafana-debugsource-0:10.2.6-9.el9_5.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- grafana-debugsource-0:10.2.6-9.el9_5.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- grafana-debugsource-0:10.2.6-9.el9_5.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- grafana-debugsource-0:10.2.6-9.el9_5.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- grafana-selinux-0:10.2.6-9.el9_5.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- grafana-selinux-0:10.2.6-9.el9_5.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- grafana-selinux-0:10.2.6-9.el9_5.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- grafana-selinux-0:10.2.6-9.el9_5.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: In cases where it is not possible to update to the latest version of go-git, it is recommended to enforce validation rules for values passed in the URL field. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.