Back to bug 2079847

Who When What Removed Added
Red Hat One Jira (issues.redhat.com) 2022-04-28 13:19:07 UTC Link ID Red Hat Issue Tracker RHCEPH-4194
Red Hat One Jira (issues.redhat.com) 2022-04-28 13:19:08 UTC Link ID Red Hat Issue Tracker RHCSDASH-730
Ernesto Puerta 2022-04-29 10:46:45 UTC Target Release 6.1 6.0
Status NEW ASSIGNED
Assignee epuertat aasharma
Priority unspecified low
Aashish sharma 2022-05-06 07:40:39 UTC Link ID Github ceph/ceph/pull/46159
Status ASSIGNED POST
Red Hat Bugzilla 2022-05-26 08:31:05 UTC CC ceph-qe-bugs
Aashish sharma 2022-07-14 08:50:04 UTC Status POST MODIFIED
errata-xmlrpc 2022-08-15 18:44:41 UTC CC tserlin
Fixed In Version ceph-17.2.3-1.el9cp
Status MODIFIED ON_QA
Sayalee 2022-08-16 19:05:16 UTC CC saraut
QA Contact sangadi saraut
Sayalee 2022-09-06 12:00:28 UTC Status ON_QA VERIFIED
Masauso Lungu 2022-09-09 09:08:59 UTC Flags needinfo?(aasharma)
CC aasharma, mlungu
Docs Contact asriram mlungu
Masauso Lungu 2022-09-19 12:07:39 UTC Flags needinfo?(aasharma)
Aashish sharma 2022-09-21 05:26:30 UTC Doc Text Cause: Enabling external grafana snapshots was a security concern

Consequence: there were CVEs reported related to this

Fix: External snapshot creation was disabled

Result: External snapshot creation is disabled in grafana
Flags needinfo?(aasharma) needinfo?(aasharma)
Doc Type If docs needed, set a value Bug Fix
Masauso Lungu 2022-09-21 18:25:49 UTC Blocks 2126050
Masauso Lungu 2022-09-27 12:30:00 UTC Doc Text Cause: Enabling external grafana snapshots was a security concern

Consequence: there were CVEs reported related to this

Fix: External snapshot creation was disabled

Result: External snapshot creation is disabled in grafana
.External snapshot creation in `Grafana` now disabled by default
Previously, creating external `grafana` snapshots would generate broken links. This would make the infrastructure vulnerable to DDoS attacks ,as someone could gain insights into the environment by looking at the metric patterns.

With this release, external Grafana snapshots are disabled and removed from the dashboard share options.
Flags needinfo?(aasharma)
Aashish sharma 2022-09-27 12:56:47 UTC Flags needinfo?(aasharma)
Masauso Lungu 2022-09-29 14:51:02 UTC Doc Text .External snapshot creation in `Grafana` now disabled by default
Previously, creating external `grafana` snapshots would generate broken links. This would make the infrastructure vulnerable to DDoS attacks ,as someone could gain insights into the environment by looking at the metric patterns.

With this release, external Grafana snapshots are disabled and removed from the dashboard share options.
.External snapshot creation in Grafana now disabled by default

Previously, creating external Grafana snapshots would generate broken links. This would make the infrastructure vulnerable to DDoS attacks ,as someone could gain insights into the environment by looking at the metric patterns.

With this release, external Grafana snapshots are disabled and removed from the dashboard share options.
Red Hat Bugzilla 2022-12-31 19:17:04 UTC CC aasharma
Assignee aasharma nia
Red Hat Bugzilla 2022-12-31 19:54:18 UTC Assignee nia nobody
Red Hat Bugzilla 2023-01-01 05:40:00 UTC CC tserlin
Red Hat Bugzilla 2023-01-01 08:41:30 UTC QA Contact saraut
CC saraut
Alasdair Kergon 2023-01-04 04:33:00 UTC Assignee nobody aasharma
Alasdair Kergon 2023-01-04 04:37:59 UTC CC aasharma
Alasdair Kergon 2023-01-04 04:48:41 UTC QA Contact saraut
Alasdair Kergon 2023-01-04 05:40:27 UTC CC saraut
Alasdair Kergon 2023-01-04 06:25:53 UTC CC tserlin
Red Hat Bugzilla 2023-01-09 08:29:32 UTC CC ceph-eng-bugs
Alasdair Kergon 2023-01-09 19:43:36 UTC CC ceph-eng-bugs
Eliska 2023-01-16 10:42:35 UTC Doc Text .External snapshot creation in Grafana now disabled by default

Previously, creating external Grafana snapshots would generate broken links. This would make the infrastructure vulnerable to DDoS attacks ,as someone could gain insights into the environment by looking at the metric patterns.

With this release, external Grafana snapshots are disabled and removed from the dashboard share options.
.External snapshot creation in Grafana now disabled by default

Previously, creating external Grafana snapshots would generate broken links. This would make the infrastructure vulnerable to DDoS attacks ,as someone could gain insights into the environment by looking at the metric patterns.

With this fix, external Grafana snapshots are disabled and removed from the dashboard share options.
CC ekristov
errata-xmlrpc 2023-03-20 18:37:43 UTC Status VERIFIED RELEASE_PENDING
errata-xmlrpc 2023-03-20 18:56:27 UTC Status RELEASE_PENDING CLOSED
Resolution --- ERRATA
Last Closed 2023-03-20 18:56:27 UTC
errata-xmlrpc 2023-03-20 18:57:02 UTC Link ID Red Hat Product Errata RHBA-2023:1360

Back to bug 2079847