发布日期: 2025-04-22
版本号: v11.4.3+security-01

Grafana 11.4.3+security-01是一个安全更新版本。该版本主要修复了两个安全漏洞:CVE-2025-3454和CVE-2025-2703。此外,更新还包括将Go版本升级到1.23.7、更新受CVE影响的依赖库,以及修复了告警、InfluxDB和公共服务账户等相关功能中的一些问题。

更新内容 (中文)

下载页面 新功能亮点

特性与增强

  • 日常维护: 将Go版本升级至1.23.7 #101582, @macabu
  • 日常维护: 将Go版本升级至1.23.7(企业版)
  • 日常维护: 更新受CVE影响的golang-gwt依赖 #102704, @grambbledook

缺陷修复

  • 告警系统: 修复基于令牌的Slack图片上传功能,支持频道名称 #101072, @JacobsonMT
  • InfluxDB: 优化正则表达式(InfluxQL)中模板变量的处理方式 #100987, @aangelisc
  • 服务账户: 避免在服务账户和渲染器用户界面流程中显示错误弹窗 #101790, @IevaVasiljeva
  • 安全修复: 修复CVE-2025-3454漏洞
  • 安全修复: 修复CVE-2025-2703漏洞

更新内容 (原始)

Download page What’s new highlights

Features and enhancements

Bug fixes

  • Alerting: Fix token-based Slack image upload to work with channel names #101072, @JacobsonMT
  • InfluxDB: Improve handling of template variables contained in regular expressions (InfluxQL) #100987, @aangelisc
  • Service Accounts: Do not show error pop-ups for Service Account and Renderer UI flows #101790, @IevaVasiljeva
  • Security: Fix CVE-2025-3454
  • Security: Fix CVE-2025-2703

下载链接