Back to bug 2138015

Who When What Removed Added
Nick Tait 2022-10-26 21:24:23 UTC CC security-response-team
Sage McTaggart 2022-10-27 00:02:05 UTC Depends On 2138035, 2138034, 2138036
Sandipan Roy 2022-10-27 06:09:46 UTC Depends On 2138070, 2138071
Borja Tarraso 2022-10-27 20:04:57 UTC Depends On 2138265
Red Hat Bugzilla 2022-10-28 13:13:03 UTC CC krathod
Avinash Hanwate 2022-11-09 04:44:37 UTC Summary EMBARGOED CVE-2022-39307 grafana: User enumeration via forget password CVE-2022-39307 grafana: User enumeration via forget password
Group qe_staff, security
CC grafana-maint
Avinash Hanwate 2022-11-09 04:45:03 UTC Depends On 2141185
Nick Tait 2022-11-11 18:18:19 UTC CC jburrell, vkumar
Nick Tait 2022-11-11 18:38:50 UTC Fixed In Version grafana 9.2.4 grafana 8.5.15
Nick Tait 2022-11-11 21:34:05 UTC Doc Text An information leak was discovered in Grafana. Remote unauthenticated users could exploit the forget password feature to discover which user accounts exist.
Red Hat Bugzilla 2023-01-01 05:32:50 UTC CC amctagga
Red Hat Bugzilla 2023-01-01 05:47:17 UTC CC flucifre
Red Hat Bugzilla 2023-01-01 05:52:50 UTC CC mhackett
Red Hat Bugzilla 2023-01-01 06:02:10 UTC CC bniver
Red Hat Bugzilla 2023-01-01 08:34:24 UTC CC mbenjamin
Red Hat Bugzilla 2023-01-01 08:43:26 UTC CC sostapov
Red Hat Bugzilla 2023-01-01 08:47:50 UTC CC vereddy
Alasdair Kergon 2023-01-04 05:43:50 UTC CC sostapov
Alasdair Kergon 2023-01-04 06:11:25 UTC CC bniver
Alasdair Kergon 2023-01-04 06:19:28 UTC CC mbenjamin
Alasdair Kergon 2023-01-04 06:29:04 UTC CC vereddy
Alasdair Kergon 2023-01-04 06:43:51 UTC CC flucifre
Alasdair Kergon 2023-01-04 11:29:24 UTC CC mhackett
Red Hat Bugzilla 2023-02-03 23:11:31 UTC CC ovanders
errata-xmlrpc 2023-06-15 16:01:20 UTC Link ID Red Hat Product Errata RHSA-2023:3642
Red Hat Bugzilla 2023-07-07 08:28:33 UTC CC security-response-team
Assignee security-response-team nobody

Back to bug 2138015