#CVE-2025-4123 for Grafana

1 messages · Page 1 of 1 (latest)

loud ether
#

Just a heads up, we got this from our security team this morning for Grafana 11.5.2 (nabox)
https://grafana.com/blog/2025/05/23/grafana-security-release-medium-and-high-severity-security-fixes-for-cve-2025-4123-and-cve-2025-3580/

Grafana Labs

Today we are releasing Grafana 12.0.1, 11.6.2, 11.5.5, 11.4.5, 11.3.7, 11.2.10, and 10.4.19, which include medium and high severity security fixes. If you are affected, we recommend that you install newly released versions.

novel horizon
#

thanks @loud ether which version of Nabox are you running? @spare junco

loud ether
#

It's 4.0.10.f9baaca

novel horizon
#

thanks

loud ether
#

i think it was the latest one but i could be wrong

#

i've slept since it was installed/updated

spare junco
#

Thanks !

onyx plover
#

I have a similar issue with the internal security
Will there be a new version of Nabox soon or is there the possibility to only update Grafana?

boreal tide
#

Plus 1 here 😇

spare junco
#

Working on it. Been working on other security configurations that were a bit of a challenge (CSP headers), looks like it is ok now.

loud ether
#

cool, the CSP stuff is one we've had for a long time but was easy to put an exception in place for

spare junco
#

4.0.11 available