Page MenuHomePhabricator

Upgrade grafana in cloudmetrics
Closed, ResolvedPublic

Description

moritz let us know that there's a new CVE for which our grafana instances are affected.

https://grafana.com/blog/2021/10/05/grafana-7.5.11-and-8.1.6-released-with-critical-security-fix/

the fixed 8.1.6 package is already on apt.wikimedia.org, so it means that we need to upgrade.

Related Objects

Event Timeline

dcaro triaged this task as High priority.Oct 6 2021, 8:24 AM
dcaro created this task.

We might want to upgrade to grafana 8 at the same time

dcaro removed dcaro as the assignee of this task.Oct 6 2021, 8:26 AM
dcaro updated the task description. (Show Details)
dcaro claimed this task.
dcaro moved this task from To refine to Done on the User-dcaro board.

Given that grafana 8 upgrade has still some things to figure out (T282863) I (with handholding by @MoritzMuehlenhoff) have downgraded the wikimedia repos grafana package to 7.5 and upgraded our clodmetrics hosts with that version.

Mentioned in SAL (#wikimedia-cloud) [2021-10-06T09:47:05Z] <dcaro> upgraded cloudmetrics to grafana 7.5 (T292614)