Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security: Do not allow an anonymous user to create snapshots. CVE-2021-27358 #31263

Merged
merged 1 commit into from
Feb 17, 2021

Conversation

marefr
Copy link
Member

@marefr marefr commented Feb 17, 2021

What this PR does / why we need it:
Disallow anonymous user to create snapshots.

Which issue(s) this PR fixes:
Fixes #

Special notes for your reviewer:

@marefr marefr requested a review from a team as a code owner February 17, 2021 08:28
@marefr marefr requested review from a team, aknuds1, ying-jeanne, peterholmberg and kaydelaney and removed request for a team February 17, 2021 08:28
@marefr marefr added this to the 7.4.2 milestone Feb 17, 2021
@marefr marefr added the old backport v7.4.x Mark PR for automatic backport to v7.4.x label Feb 17, 2021
Copy link
Member

@torkelo torkelo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

@marefr marefr merged commit 8f20b13 into master Feb 17, 2021
@marefr marefr deleted the snapshot_anonymous branch February 17, 2021 08:51
grafanabot pushed a commit that referenced this pull request Feb 17, 2021
marefr added a commit that referenced this pull request Feb 17, 2021
(cherry picked from commit 8f20b13)

Co-authored-by: Marcus Efraimsson <marcus.efraimsson@gmail.com>
@wbrowne wbrowne changed the title Snapshots: Disallow anonymous user to create snapshots Snapshots: Do not allow an anonymous user to create snapshots Feb 17, 2021
@torkelo torkelo changed the title Snapshots: Do not allow an anonymous user to create snapshots Security: Do not allow an anonymous user to create snapshots Feb 23, 2021
@torkelo torkelo changed the title Security: Do not allow an anonymous user to create snapshots Security: Do not allow an anonymous user to create snapshots. CVE-2021-27358 Mar 8, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
add to changelog area/security old backport v7.4.x Mark PR for automatic backport to v7.4.x
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants