In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.
References
Configurations
History
No history.
Information
Published : 2020-04-29 16:15
Updated : 2024-11-21 04:59
NVD link : CVE-2020-12459
Mitre link : CVE-2020-12459
CVE.ORG link : CVE-2020-12459
JSON object : View
Products Affected
fedoraproject
- fedora
grafana
- grafana
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource