FlawAtlas
Search the atlas
CVE-2019-19499 Moderate

Arbitrary file read in github.com/grafana/grafana

An authenticated attacker that has privileges to modify the data source configurations can read arbitrary files.

Exploit probability 3.6%
Published March 28, 2024
Required by Not available
Last source change June 19, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

49 explicit affected versions

Go github.com/grafana/grafana
Go github.com/grafana/grafana

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2019-19499

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

View original source
Open Source Vulnerabilities GHSA-4pwp-cx67-5cpx

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

View original source
Open Source Vulnerabilities GO-2024-2661

An authenticated attacker that has privileges to modify the data source configurations can read arbitrary files.

View original source

05 / REFERENCES

Further evidence