PT-2020-10171 · Grafana+4 · Grafana+4
Yuriy Dyachenko
·
Published
2020-03-03
·
Updated
2024-03-28
·
CVE-2019-19499
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Grafana versions 6.4.3 and earlier
Description
The issue allows an authenticated attacker with privileges to modify data source configurations to read arbitrary files. This can be exploited by an attacker who has the necessary permissions to access and modify the data source configurations.
Recommendations
For Grafana versions 6.4.3 and earlier, update to a version later than 6.4.3 to resolve the issue.
At the moment, there is no information about other specific fixes for this vulnerability.
Exploit
Fix
Information Disclosure
Path traversal
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Grafana
Red Hat