grafana v11.5.3+security-01 版本更新介绍
发布日期: 2025-04-22
版本号: v11.5.3+security-01
Grafana 11.5.3 安全版本主要更新内容包括:将 Go 版本升级至 1.23.7 并更新了受 CVE 影响的依赖项。修复了多个问题,包括:Slack 图片上传、AzureAD 配置界面、仪表板保存时意外更新时间范围与变量、仪表板返回快捷键、InfluxQL 模板变量处理、LDAP 测试页面崩溃以及组织间链接跳转等。此外,还修复了两个安全漏洞 CVE-2025-3454 和 CVE-2025-2703。
更新内容 (中文)
功能和增强
- 杂项: 将 Go 升级到 1.23.7 #101581, @macabu
- 杂项: 将 Go 升级到 1.23.7(企业版)
- 杂项: 更新受 CVE 影响的依赖项 #102709, @grambbledook
错误修复
- 告警: 修复基于令牌的 Slack 图片上传以支持频道名称 #101078, @JacobsonMT
- 认证: 修复 AzureAD 配置 UI 的 ClientAuthentication 下拉菜单 #100869, @mgyongyosi
- 仪表盘: 修复保存时意外更新时间范围和变量的问题 #101671, @harisrozajac
- 仪表盘: 修复缺失
v/e/i键绑定以返回仪表盘 #102365, @mdvictor - InfluxDB: 改进对正则表达式中模板变量的处理(InfluxQL) #100977, @aangelisc
- LDAP 测试: 修复页面崩溃问题 #102683, @ashharrison90
- 组织重定向: 修复组织间链接问题 #102089, @ashharrison90
- 安全: 修复 CVE-2025-3454
- 安全: 修复 CVE-2025-2703
更新内容 (原始)
Download page What’s new highlights
Features and enhancements
- Chore: Bump Go to 1.23.7 #101581, @macabu
- Chore: Bump Go to 1.23.7 (Enterprise)
- Chore: Update CVE-affected dependencies #102709, @grambbledook
Bug fixes
- Alerting: Fix token-based Slack image upload to work with channel names #101078, @JacobsonMT
- Auth: Fix AzureAD config UI’s ClientAuthentication dropdown #100869, @mgyongyosi
- Dashboard: Fix the unintentional time range and variables updates on saving #101671, @harisrozajac
- Dashboards: Fix missing
v/e/ikeybindings to return back to dashboard #102365, @mdvictor - InfluxDB: Improve handling of template variables contained in regular expressions (InfluxQL) #100977, @aangelisc
- LDAP test: Fix page crash #102683, @ashharrison90
- Org redirection: Fix linking between orgs #102089, @ashharrison90
- Security: Fix CVE-2025-3454
- Security: Fix CVE-2025-2703