Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2018-12-13 19:29
Updated : 2024-11-21 03:57
NVD link : CVE-2018-19039
Mitre link : CVE-2018-19039
CVE.ORG link : CVE-2018-19039
JSON object : View
Products Affected
redhat
- enterprise_linux_workstation
- ceph_storage
- enterprise_linux_desktop
- enterprise_linux_server
netapp
- active_iq_performance_analytics_services
- storagegrid_webscale_nas_bridge
grafana
- grafana
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor