grafana v11.4.3+security-01 版本更新介绍
发布日期: 2025-04-22
版本号: v11.4.3+security-01
Grafana 11.4.3+security-01是一个安全更新版本。该版本主要修复了两个安全漏洞:CVE-2025-3454和CVE-2025-2703。此外,更新还包括将Go版本升级到1.23.7、更新受CVE影响的依赖库,以及修复了告警、InfluxDB和公共服务账户等相关功能中的一些问题。
更新内容 (中文)
特性与增强
- 日常维护: 将Go版本升级至1.23.7 #101582, @macabu
- 日常维护: 将Go版本升级至1.23.7(企业版)
- 日常维护: 更新受CVE影响的golang-gwt依赖 #102704, @grambbledook
缺陷修复
- 告警系统: 修复基于令牌的Slack图片上传功能,支持频道名称 #101072, @JacobsonMT
- InfluxDB: 优化正则表达式(InfluxQL)中模板变量的处理方式 #100987, @aangelisc
- 服务账户: 避免在服务账户和渲染器用户界面流程中显示错误弹窗 #101790, @IevaVasiljeva
- 安全修复: 修复CVE-2025-3454漏洞
- 安全修复: 修复CVE-2025-2703漏洞
更新内容 (原始)
Download page What’s new highlights
Features and enhancements
- Chore: Bump Go to 1.23.7 #101582, @macabu
- Chore: Bump Go to 1.23.7 (Enterprise)
- Chore: Update CVE-affected golang-gwt dependencies #102704, @grambbledook
Bug fixes
- Alerting: Fix token-based Slack image upload to work with channel names #101072, @JacobsonMT
- InfluxDB: Improve handling of template variables contained in regular expressions (InfluxQL) #100987, @aangelisc
- Service Accounts: Do not show error pop-ups for Service Account and Renderer UI flows #101790, @IevaVasiljeva
- Security: Fix CVE-2025-3454
- Security: Fix CVE-2025-2703