Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Security: Do not allow an anonymous user to create snapshots. CVE-2021-27358 #31263

Merged
merged 1 commit into from
Feb 17, 2021

Conversation

marefr
Copy link
Member

@marefr marefr commented Feb 17, 2021

What this PR does / why we need it:
Disallow anonymous user to create snapshots.

Which issue(s) this PR fixes:
Fixes #

Special notes for your reviewer:

@marefr marefr requested a review from a team as a code owner February 17, 2021 08:28
@marefr marefr requested review from a team, aknuds1, ying-jeanne, peterholmberg and kaydelaney and removed request for a team February 17, 2021 08:28
@marefr marefr added this to the 7.4.2 milestone Feb 17, 2021
@marefr marefr added the old backport v7.4.x Mark PR for automatic backport to v7.4.x label Feb 17, 2021
Copy link
Member

@torkelo torkelo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

@marefr marefr merged commit 8f20b13 into master Feb 17, 2021
@marefr marefr deleted the snapshot_anonymous branch February 17, 2021 08:51
grafanabot pushed a commit that referenced this pull request Feb 17, 2021
marefr added a commit that referenced this pull request Feb 17, 2021
(cherry picked from commit 8f20b13)

Co-authored-by: Marcus Efraimsson <marcus.efraimsson@gmail.com>
@wbrowne wbrowne changed the title Snapshots: Disallow anonymous user to create snapshots Snapshots: Do not allow an anonymous user to create snapshots Feb 17, 2021
@torkelo torkelo changed the title Snapshots: Do not allow an anonymous user to create snapshots Security: Do not allow an anonymous user to create snapshots Feb 23, 2021
@torkelo torkelo changed the title Security: Do not allow an anonymous user to create snapshots Security: Do not allow an anonymous user to create snapshots. CVE-2021-27358 Mar 8, 2021
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
add to changelog area/security old backport v7.4.x Mark PR for automatic backport to v7.4.x
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants