rpm package
opensuse/supportutils-plugin-salt&distro=openSUSE Leap 15.4
pkg:rpm/opensuse/supportutils-plugin-salt&distro=openSUSE%20Leap%2015.4
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-41723 | — | < 1.2.2-150000.3.13.1 | 1.2.2-150000.3.13.1 | Feb 28, 2023 | A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests. | ||
| CVE-2022-23552 | — | < 1.2.2-150000.3.13.1 | 1.2.2-150000.3.13.1 | Jan 27, 2023 | Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions 8.5.16, 9.2.10, and 9.3.4, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible because SVG files | ||
| CVE-2022-39324 | — | < 1.2.2-150000.3.13.1 | 1.2.2-150000.3.13.1 | Jan 27, 2023 | Grafana is an open-source platform for monitoring and observability. Prior to versions 8.5.16 and 9.2.8, malicious user can create a snapshot and arbitrarily choose the `originalUrl` parameter by editing the query, thanks to a web proxy. When another user opens the URL of the sna | ||
| CVE-2022-46146 | — | < 1.2.2-150000.3.13.1 | 1.2.2-150000.3.13.1 | Nov 29, 2022 | Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the built-in authentication cache. Versions 0.7.2 and 0. |
- CVE-2022-41723Feb 28, 2023affected < 1.2.2-150000.3.13.1fixed 1.2.2-150000.3.13.1
A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.
- CVE-2022-23552Jan 27, 2023affected < 1.2.2-150000.3.13.1fixed 1.2.2-150000.3.13.1
Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions 8.5.16, 9.2.10, and 9.3.4, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible because SVG files
- CVE-2022-39324Jan 27, 2023affected < 1.2.2-150000.3.13.1fixed 1.2.2-150000.3.13.1
Grafana is an open-source platform for monitoring and observability. Prior to versions 8.5.16 and 9.2.8, malicious user can create a snapshot and arbitrarily choose the `originalUrl` parameter by editing the query, thanks to a web proxy. When another user opens the URL of the sna
- CVE-2022-46146Nov 29, 2022affected < 1.2.2-150000.3.13.1fixed 1.2.2-150000.3.13.1
Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the built-in authentication cache. Versions 0.7.2 and 0.