The vendor explicitly identifies these products as affected by this CVE.
- servicemesh-grafana as a component of OpenShift Service Mesh 2.0
- servicemesh-grafana-prometheus as a component of OpenShift Service Mesh 2.0
- servicemesh-grafana.src as a component of OpenShift Service Mesh 2.0
- servicemesh-grafana as a component of OpenShift Service Mesh 2.1
- servicemesh-grafana.src as a component of OpenShift Service Mesh 2.1
- grafana.src as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- grafana as a component of Red Hat Ceph Storage 2
- grafana.src as a component of Red Hat Ceph Storage 2
- grafana as a component of Red Hat Ceph Storage 3
- grafana-container as a component of Red Hat Ceph Storage 3
- grafana.src as a component of Red Hat Ceph Storage 3
- rhceph/rhceph-4-dashboard-rhel8 as a component of Red Hat Ceph Storage 4
- Summary
- An information-disclosure flaw was found in grafana. When a data source has the Forward OAuth Identity feature enabled, sending a query to that data source with an API token (and no other user credentials) will forward the OAuth Identity of the most recently logged-in user. This flaw allows API token holders to retrieve data to which they may not be authorized.
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/2789521 For supported configurations, refer to: https://access.redhat.com/articles/1548993
