[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:21351-1":6},{"stargazers_count":4,"fetched_at":5},7,"2026-07-31T23:19:30.300Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":20,"duplicates":21,"related":22,"reserved_at":9,"published_at":26,"modified_at":27,"state":9,"summary":28,"references_raw":30,"kevs":54,"epss":9,"epss_history":55,"metrics":56,"affected":57},"OPENSUSE-SU-2026:21351-1","Security update for grafana\n\nThis update for grafana fixes the following issues:\n\nChanges in grafana:\n\n- Add UI web assets as additional source tarball\n\n- Update to version 12.4.5 (jsc#PED-16512):\n  * Datasources: return 400 when payload UID does not match URL UID\n    in PUT /api/datasources/uid/:uid\n\n- Update to version 12.4.4:\n  * Security and quality updates.\n  * Various bug fixes and enhancements.\n\n- Update to version 12.4.3:\n  * Analytics: Keep internal dashboard id.\n  * Go: Update to 1.25.9.\n  * Reporting: Correctly apply appSubURL to report settings\n               requests.\n  * Alerting: Document Grafana HA Alertmanager cluster metrics\n              prefix change.\n\n- Update to version 12.4.2:\n  * Various bug fixes and performance improvements.\n  * Dependency updates to core plugins and UI libraries.\n\n- Update to version 12.4.1:\n  * Bug fixes and minor quality-of-life enhancements.\n  * Updates to data source provisioning and dashboard schemas.\n\n- Update to version 12.4.0:\n  * Introduced dynamic dashboards in public preview.\n  * Added a new side toolbar that replaces the second top toolbar\n    to provide additional vertical space.\n  * Added the ability to create dashboards from templates using\n    sample data.\n  * Revamped the gauge visualization with rounded bars,\n    configurable bar thickness, and endpoint markers.\n  * Added support to map one variable to multiple values.\n  * CVE-2025-12141: Fixed information leakage in Grafana Alerting\n    (bsc#1262187)\n\n- Update to version 12.3.0:\n  * Released a completely redesigned logs visualization.\n  * Added the ability to export dashboards directly as PNG images.\n  * Introduced an interactive learning experience within the\n    Grafana UI.\n  * Added a Switch template variable type to quickly toggle between\n    values in queries.\n  * Added functionality to style table cells using CSS properties\n    via the field cell option.\n\n- Update to version 12.2.0:\n  * Routine feature enhancements, minor bug fixes, and security\n    patches.\n\n- Update to version 12.1.0:\n  * Added support for Entra Workload Identity to enhance\n    authentication capabilities with federated credentials.\n  * Redesigned the alert rule list page.\n  * Renamed Mute Timings to Active Time Intervals in Grafana\n    Alerting.\n  * Added support for Service Account Impersonation in the BigQuery\n    data source.\n  * Introduced the Grafana Advisor in public preview.\n\n- Update to version 12.0.0:\n  * BREAKING: Removed AngularJS and all deprecated UI Extensions\n    APIs.\n  * BREAKING: Enforced stricter version compatibility checks in\n    plugin CLI install commands.\n  * BREAKING: Enabled the failWrongDSUID feature flag by default,\n    which rejects data sources with incorrect UIDs.\n  * MIGRATION: Triggered a full-table rewrite for the annotation\n    table, which may temporarily increase disk usage.\n  * Introduced a new dashboard schema to replace the original\n    single grid layout.\n\n- CVE-2026-41607: Fix potential information disclosure in Apache\n  Thrift (bsc#1263272)\n",null,[],[],[],[14,16,18],{"_key":15},"CVE-2025-12141",{"_key":17},"CVE-2026-21725",{"_key":19},"CVE-2026-41607",[],[],[23,24,25],{"_key":15},{"_key":17},{"_key":19},"2026-07-14T09:22:23Z","2026-07-15T10:00:12.751955097Z",{"cisa_kev":29,"cisa_ransomware":29,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[31,37,41,46,50],{"url":32,"sources":33,"tags":35},"https://bugzilla.suse.com/1262187",[34],"osv_opensuse",[36],"REPORT",{"url":38,"sources":39,"tags":40},"https://bugzilla.suse.com/1263272",[34],[36],{"url":42,"sources":43,"tags":44},"https://www.suse.com/security/cve/CVE-2025-12141",[34],[45],"WEB",{"url":47,"sources":48,"tags":49},"https://www.suse.com/security/cve/CVE-2026-21725",[34],[45],{"url":51,"sources":52,"tags":53},"https://www.suse.com/security/cve/CVE-2026-41607",[34],[45],[],[],[],[58],{"ecosystem":59,"name":60,"vendor":61,"product":62,"cpe_part":9,"purl_type":63,"purl_namespace":61,"purl_name":62,"source":9,"versions":64},"openSUSE","grafana","opensuse","grafana&distro=openSUSE Leap 16.0","rpm",[65],{"version":66,"is_range":67,"range_type":68,"version_start":9,"version_start_type":9,"version_end":69,"version_end_type":70,"fixed_in":9},"lt12_4_5_bp160_1_1",true,"ecosystem","12.4.5-bp160.1.1","excluding"]