Compare commits
1 commit
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
7d8123ea3e |
2 changed files with 28 additions and 1 deletions
21
0013-snapshot-delete-check-org.patch
Normal file
21
0013-snapshot-delete-check-org.patch
Normal file
|
|
@ -0,0 +1,21 @@
|
|||
From 9c1236ba6e7d4c6506c62adeb830d9e56db7f425 Mon Sep 17 00:00:00 2001
|
||||
From: Sam Feifer <sfeifer@redhat.com>
|
||||
Date: Thu, 28 Mar 2024 13:24:35 -0400
|
||||
Subject: [PATCH] snapshot delete check org
|
||||
|
||||
|
||||
diff --git a/pkg/api/dashboard_snapshot.go b/pkg/api/dashboard_snapshot.go
|
||||
index 47ae50544a..0007e89ccb 100644
|
||||
--- a/pkg/api/dashboard_snapshot.go
|
||||
+++ b/pkg/api/dashboard_snapshot.go
|
||||
@@ -328,6 +328,10 @@ func (hs *HTTPServer) DeleteDashboardSnapshot(c *models.ReqContext) response.Res
|
||||
return response.Error(http.StatusNotFound, "Failed to get dashboard snapshot", nil)
|
||||
}
|
||||
|
||||
+ if query.Result.OrgId != c.OrgID {
|
||||
+ return response.Error(http.StatusUnauthorized, "OrgID mismatch", nil)
|
||||
+ }
|
||||
+
|
||||
if query.Result.External {
|
||||
err := deleteExternalDashboardSnapshot(query.Result.ExternalDeleteUrl)
|
||||
if err != nil {
|
||||
|
|
@ -25,7 +25,7 @@ end}
|
|||
|
||||
Name: grafana
|
||||
Version: 9.2.10
|
||||
Release: 17%{?dist}
|
||||
Release: 18%{?dist}
|
||||
Summary: Metrics dashboard and graph editor
|
||||
License: AGPL-3.0-only
|
||||
URL: https://grafana.org
|
||||
|
|
@ -79,6 +79,7 @@ Patch9: 0009-redact-weak-ciphers.patch
|
|||
Patch10: 0010-skip-tests.patch
|
||||
Patch11: 0011-remove-email-lookup.patch
|
||||
Patch12: 0012-coredump-selinux-error.patch
|
||||
Patch13: 0013-snapshot-delete-check-org.patch
|
||||
|
||||
# Patches affecting the vendor tarball
|
||||
Patch1001: 1001-vendor-patch-removed-backend-crypto.patch
|
||||
|
|
@ -764,6 +765,7 @@ cp -p %{SOURCE8} %{SOURCE9} %{SOURCE10} SELinux
|
|||
%patch -P 10 -p1
|
||||
%patch -P 11 -p1
|
||||
%patch -P 12 -p1
|
||||
%patch -P 13 -p1
|
||||
|
||||
%patch -P 1001 -p1
|
||||
%if %{enable_fips_mode}
|
||||
|
|
@ -1006,6 +1008,10 @@ fi
|
|||
%{_datadir}/selinux/*/grafana.pp
|
||||
|
||||
%changelog
|
||||
* Thu Mar 28 2024 Sam Feifer <sfeifer@redhat.com> 9.2.10-18
|
||||
- Check OrdID is correct before deleting snapshot
|
||||
- fix CVE-2024-1313
|
||||
|
||||
* Wed Jan 31 2024 Sam Feifer <sfeifer@redhat.com> 9.2.10-17
|
||||
- Allows for postgreSQL datasource in selinux policy
|
||||
- grafana-cli wrapper script now allows for the gid to be 0
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue