The vendor explicitly identifies these products as affected by this CVE.
- openshift-service-mesh/grafana-rhel8 as a component of OpenShift Service Mesh 2.0
- servicemesh-grafana as a component of OpenShift Service Mesh 2.0
- servicemesh-grafana-prometheus as a component of OpenShift Service Mesh 2.0
- servicemesh-grafana.src as a component of OpenShift Service Mesh 2.0
- openshift-service-mesh/grafana-rhel8 as a component of OpenShift Service Mesh 2.1
- servicemesh-grafana as a component of OpenShift Service Mesh 2.1
- servicemesh-grafana.src as a component of OpenShift Service Mesh 2.1
- rhacm2/acm-grafana-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- grafana as a component of Red Hat Ceph Storage 3
- grafana.src as a component of Red Hat Ceph Storage 3
- rhceph/rhceph-4-dashboard-rhel8 as a component of Red Hat Ceph Storage 4
- rhceph/rhceph-5-dashboard-rhel8 as a component of Red Hat Ceph Storage 5
- Summary
- An information leak was discovered in Grafana. Remote unauthenticated users could exploit the forget password feature to discover which user accounts exist.
- Remediation
- For details on how to apply this update, see Upgrade a Red Hat Ceph Storage cluster using cephadm in the Red Hat Storage Ceph Upgrade Guide.(https://access.redhat.com/documentation/en-us/red_hat_ceph_storage)
