From 9265c1d7a703de3f1dd9e05e2815758b9a10f63d Mon Sep 17 00:00:00 2001 From: William Dumont Date: Thu, 19 Sep 2024 15:38:33 +0200 Subject: [PATCH 1/4] fix changelog --- CHANGELOG.md | 4 ---- 1 file changed, 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index dc4732971e1d..5f9c7f935a3a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -10,10 +10,6 @@ internal API changes are not present. v0.43.1 (2024-09-19) ------------------------- -### Security fixes - -- Add quotes to windows service path to prevent path interception attack. (@wildum) - v0.43.0 (2024-09-11) ------------------------- From 090cf4407e044787f0fb393d2c08f887d1eb3c49 Mon Sep 17 00:00:00 2001 From: William Dumont Date: Wed, 25 Sep 2024 11:50:35 +0200 Subject: [PATCH 2/4] add changelog entry --- CHANGELOG.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 5f9c7f935a3a..fe6810dc0d85 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,9 +7,13 @@ This document contains a historical list of changes between releases. Only changes that impact end-user behavior are listed; changes to documentation or internal API changes are not present. -v0.43.1 (2024-09-19) +v0.43.1 (2024-09-25) ------------------------- +### Security fixes + +- Add quotes to windows service path to prevent path interception attack. (CVE-2024-8996) (@wildum) + v0.43.0 (2024-09-11) ------------------------- From d62d5bb0c7a35e10b4cb06203a6a4a6841869bf8 Mon Sep 17 00:00:00 2001 From: William Dumont Date: Wed, 25 Sep 2024 11:57:21 +0200 Subject: [PATCH 3/4] update patch version --- CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index fe6810dc0d85..1a206638526c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,7 +7,7 @@ This document contains a historical list of changes between releases. Only changes that impact end-user behavior are listed; changes to documentation or internal API changes are not present. -v0.43.1 (2024-09-25) +v0.43.2 (2024-09-25) ------------------------- ### Security fixes From 1316da08d64a6fb9c30fe54e9bb98860652e1790 Mon Sep 17 00:00:00 2001 From: William Dumont Date: Wed, 25 Sep 2024 12:02:01 +0200 Subject: [PATCH 4/4] add cve link --- CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 1a206638526c..e58932aba3ba 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -12,7 +12,7 @@ v0.43.2 (2024-09-25) ### Security fixes -- Add quotes to windows service path to prevent path interception attack. (CVE-2024-8996) (@wildum) +- Add quotes to windows service path to prevent path interception attack. [CVE-2024-8996](https://grafana.com/security/security-advisories/cve-2024-8996/) (@wildum) v0.43.0 (2024-09-11) -------------------------