Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-19039

Опубликовано: 13 нояб. 2018
Источник: redhat
CVSS3: 6.5
EPSS Средний

Описание

Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.

A security issue was found that could allow any users with Editor or Admin permissions in Grafana to read any file that the Grafana process can read from the filesystem. However, in order to exploit this issue you would need to be logged in to the system as a legitimate user with Editor or Admin permissions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11openshift3/grafanaAffected
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaNot affected
Red Hat OpenStack Platform 8 (Liberty) Operational ToolsgrafanaWill not fix
Red Hat OpenStack Platform 9 (Mitaka) Operational ToolsgrafanaWill not fix
Red Hat Storage 3grafanaAffected
Red Hat Ceph Storage 2.5 for Red Hat Enterprise Linux 7cephFixedRHSA-2019:074711.04.2019
Red Hat Ceph Storage 2.5 for Red Hat Enterprise Linux 7grafanaFixedRHSA-2019:074711.04.2019
Red Hat Ceph Storage 3.2cephFixedRHSA-2019:091130.04.2019
Red Hat Ceph Storage 3.2ceph-ansibleFixedRHSA-2019:091130.04.2019
Red Hat Ceph Storage 3.2grafanaFixedRHSA-2019:091130.04.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200

EPSS

Процентиль: 94%
0.12622
Средний

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 6 лет назад

Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.

CVSS3: 6.5
nvd
больше 6 лет назад

Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.

CVSS3: 6.5
debian
больше 6 лет назад

Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated ...

CVSS3: 6.5
github
около 3 лет назад

Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.

EPSS

Процентиль: 94%
0.12622
Средний

6.5 Medium

CVSS3