FlawAtlas
Search the atlas
CVE-2020-12459 High

Grafana world readable configuration files

In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files `/etc/grafana/grafana.ini` and `/etc/grafana/ldap.toml` (which contain a secret_key and a bind_password) are world readable.

Exploit probability 0.3%
Published May 24, 2022
Required by Not available
Last source change June 19, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown
Go github.com/grafana/grafana
Go github.com/grafana/grafana
Bitnami grafana

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2020-12459

In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.

View original source
Open Source Vulnerabilities GO-2024-2519

Grafana world readable configuration files in github.com/grafana/grafana. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/grafana/grafana from v6.0.0 before v7.2.1.

View original source
Open Source Vulnerabilities GHSA-m25m-5778-fm22

In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files `/etc/grafana/grafana.ini` and `/etc/grafana/ldap.toml` (which contain a secret_key and a bind_password) are world readable.

View original source
Open Source Vulnerabilities BIT-grafana-2020-12459

In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.

View original source

05 / REFERENCES

Further evidence