Upgrade grafana on PMM2 on AWS AMI

Description:

I installed PMM from AWS AMI images, I did yum update and updated all packages, I am using AWS Inspector to monitor servers vulnerabilities, the inspector show that there are 5 critical vulnerabilities on Grafan, I need to find how can I upgrade Grafana version to latest and fix these vulnerabilities

Steps to Reproduce:

install PMM 2 on AWS from AMI image

Version:

[root@pmm-server grafana]# grafana -v
grafana version 9.2.20
PMM version: 2.44.0

more details from Vanta about this issue

Package name

Installed version

v0.0.0-20240319182150-590c657828b5

Fixed version

5.2.3

Remediation

None Provided

Vulnerabilities

CVE-2018-15727

Hello, as we use forked version of grafana it’s not possible to upgrade to upstream grafana. We are finishing PMM 3 release preparation where we have Grafana 11. I recommend to wait for PMM 3 release and then upgrade to it.

Hi Nurian,

Thanks for your reply, I saw in the PMM website that PMM 3 is released, but the migration instructions is for docker setup, I want to ask when I can do the upgrade on my AMI image installed version, using Oracle linux 9 on AWS

Thanks

Hi Khaled,

Normally we need a few more days until we get the AMI image scanned and approved by AWS. It will then show up as available on their Marketplace.