Skip to content

[release-12.3.3] Security(Public dashboards annotations): use dashboard timerange if time selection disabled#117860

Merged
Proximyst merged 1 commit intorelease-12.3.3from
mariell/apply-patch-650-12.3.3
Feb 11, 2026
Merged

[release-12.3.3] Security(Public dashboards annotations): use dashboard timerange if time selection disabled#117860
Proximyst merged 1 commit intorelease-12.3.3from
mariell/apply-patch-650-12.3.3

Conversation

@Proximyst
Copy link
Member

Backport of #117854

Fixes: CVE-2026-21722

…ime selection disabled

Applies patch 650.

(cherry picked from commit 0c13fff)
@Proximyst Proximyst self-assigned this Feb 11, 2026
@Proximyst Proximyst marked this pull request as ready for review February 11, 2026 11:53
@Proximyst Proximyst requested a review from a team as a code owner February 11, 2026 11:53
@Proximyst Proximyst merged commit 8fe97ba into release-12.3.3 Feb 11, 2026
171 of 175 checks passed
@Proximyst Proximyst deleted the mariell/apply-patch-650-12.3.3 branch February 11, 2026 11:59
@grafana-delivery-bot
Copy link
Contributor

🚀 Your submission is now being built and packaged.

dadezzz pushed a commit to dadezzz/kubernetes that referenced this pull request Feb 13, 2026
…#386)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [docker.io/grafana/grafana](https://github.com/grafana/grafana) | patch | `12.3.2` → `12.3.3` |

---

> ⚠️ **Warning**
>
> Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

---

### Release Notes

<details>
<summary>grafana/grafana (docker.io/grafana/grafana)</summary>

### [`v12.3.3`](https://github.com/grafana/grafana/blob/HEAD/CHANGELOG.md#1233-2026-02-12)

[Compare Source](grafana/grafana@v12.3.2...v12.3.3)

##### Features and enhancements

- **Alerting:** Add limits for the size of expanded notification templates [#&#8203;117709](grafana/grafana#117709), [@&#8203;yuri-tceretian](https://github.com/yuri-tceretian)
- **Correlations:** Remove support for org\_id=0 [#&#8203;116934](grafana/grafana#116934), [@&#8203;gelicia](https://github.com/gelicia)
- **Go:** Update to 1.25.7 [#&#8203;117471](grafana/grafana#117471), [@&#8203;macabu](https://github.com/macabu)
- **Security(Public dashboards annotations):** use dashboard timerange if time selection disabled [#&#8203;117860](grafana/grafana#117860), [@&#8203;dana-axinte](https://github.com/dana-axinte)
- **Security(TraceView):** Sanitize html [#&#8203;117866](grafana/grafana#117866), [@&#8203;github-actions\[bot\]](https://github.com/github-actions\[bot])

<!-- 12.3.3 END -->

<!-- 12.3.2+security-01 START -->

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45Ni4yIiwidXBkYXRlZEluVmVyIjoiNDIuOTYuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Co-authored-by: Renovate Bot <renovate@zarantonello.dev>
Co-committed-by: Renovate Bot <renovate@zarantonello.dev>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants