sexibytes / sexigraf

SexiGraf is a vSphere centric Graphite appliance with a Grafana frontend.
http://www.sexigraf.fr
MIT License
128 stars 21 forks source link

Sexigraf "Victory Mine" impacted by Grafana CVE-2023-4822 ? #371

Closed fbellavia closed 11 months ago

fbellavia commented 11 months ago

Hello, I'm working with Sexigraf "Victory Mine", and I would like to confirm with you if this version is impacted by the CVE-2023-4822. https://grafana.com/blog/2023/10/13/grafana-security-release-new-versions-of-grafana-with-a-medium-severity-security-fix-for-cve-2023-4822/ I understand that this vulnerability impact only RBAC on Grafana Entreprise, but I would like be sure. Thanks in advance for you help. Best Regards,

rschitz commented 11 months ago

Hi, yes it's only Grafana Entreprise, not the OSS 8.5.x version we use. Next release will be out soon so stay tuned ;)

fbellavia commented 11 months ago

Thank you for your quick answer ;-)