Описание
Grafana world readable configuration files
In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini
and /etc/grafana/ldap.toml
(which contain a secret_key and a bind_password) are world readable.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-12459
- https://github.com/grafana/grafana/issues/8283
- https://github.com/grafana/grafana/commit/102448040d5132460e3b0013e03ebedec0677e00
- https://access.redhat.com/security/cve/CVE-2020-12459
- https://bugzilla.redhat.com/show_bug.cgi?id=1827765
- https://bugzilla.redhat.com/show_bug.cgi?id=1829724
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CTQCKJZZYXMCSHJFZZ3YXEO5NUBANGZS
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WEBCIEVSYIDDCA7FTRS2IFUOYLIQU34A
- https://security.netapp.com/advisory/ntap-20200518-0004
- https://src.fedoraproject.org/rpms/grafana/c/fab93d67363eb0a9678d9faf160cc88237f26277
Пакеты
github.com/grafana/grafana
>= 6.0, < 7.2.1
7.2.1
EPSS
7.1 High
CVSS4
5.5 Medium
CVSS3
CVE ID
Дефекты
Связанные уязвимости
In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.
In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.
ELSA-2020-4682: grafana security, bug fix, and enhancement update (MODERATE)
EPSS
7.1 High
CVSS4
5.5 Medium
CVSS3