Arbitrary file read in github.com/grafana/grafana
An authenticated attacker that has privileges to modify the data source configurations can read arbitrary files.
02 / AFFECTED SOFTWARE
Affected packages
49 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.
An authenticated attacker that has privileges to modify the data source configurations can read arbitrary files.
05 / REFERENCES
Further evidence
- https://security.netapp.com/advisory/ntap-20200918-0003/
- https://swarm.ptsecurity.com/grafana-6-4-3-arbitrary-file-read/
- https://github.com/grafana/grafana
- https://github.com/grafana/grafana/blob/master/CHANGELOG.md#644-2019-11-06
- https://github.com/grafana/grafana/commit/19dbd27c5caa1a160bd5854b65a4e1fe2a8a4f00
- https://github.com/grafana/grafana/pull/20192
- https://nvd.nist.gov/vuln/detail/CVE-2019-19499
- https://security.netapp.com/advisory/ntap-20200918-0003
- https://swarm.ptsecurity.com/grafana-6-4-3-arbitrary-file-read