grafana v11.3.5+security-01 版本更新介绍
发布日期: 2025-04-22
版本号: v11.3.5+security-01
Grafana发布了11.3.5安全版本。此次更新主要包含功能增强和错误修复。功能方面,将Go语言版本升级至1.23.7,并更新了存在CVE漏洞的依赖库。错误修复部分,解决了Alerting中基于令牌的Slack图片上传问题、Service Accounts和Renderer的UI流程错误弹窗,并修复了两个安全漏洞CVE-2025-3454和CVE-2025-2703。
更新内容 (中文)
特性与增强
- 杂务: 升级Go至1.23.7 #101583,@macabu
- 杂务: 升级Go至1.23.7(企业版)
- 杂务: 更新含CVE依赖项的库 #102710,@grambbledook
错误修复
- 告警: 修复基于令牌的Slack图像上传对频道名称的支持 #101488,@moustafab
- 服务账户: 在服务账户和渲染器UI流程中不再显示错误弹窗 #101791,@IevaVasiljeva
- 安全: 修复CVE-2025-3454
- 安全: 修复CVE-2025-2703
更新内容 (原始)
Download page What’s new highlights
Features and enhancements
- Chore: Bump Go to 1.23.7 #101583, @macabu
- Chore: Bump Go to 1.23.7 (Enterprise)
- Chore: Update libs with CVE in dependencies #102710, @grambbledook
Bug fixes
- Alerting: Fix token-based Slack image upload to work with channel names #101488, @moustafab
- Service Accounts: Do not show error pop-ups for Service Account and Renderer UI flows #101791, @IevaVasiljeva
- Security: Fix CVE-2025-3454
- Security: Fix CVE-2025-2703