Описание
Grafana Arbitrary File Read
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2019-19499
- https://github.com/grafana/grafana/pull/20192
- https://github.com/grafana/grafana/commit/19dbd27c5caa1a160bd5854b65a4e1fe2a8a4f00
- https://github.com/grafana/grafana/blob/master/CHANGELOG.md#644-2019-11-06
- https://security.netapp.com/advisory/ntap-20200918-0003
Пакеты
github.com/grafana/grafana
< 6.4.4
6.4.4
EPSS
5.7 Medium
CVSS4
6.5 Medium
CVSS3
CVE ID
Дефекты
Связанные уязвимости
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could ...
ELSA-2020-4682: grafana security, bug fix, and enhancement update (MODERATE)
EPSS
5.7 Medium
CVSS4
6.5 Medium
CVSS3