Information disclosure in Grafana - CVE-2018-19039

 

Information disclosure in Grafana - CVE-2018-19039

Published: November 15, 2018 / Updated: November 16, 2018


Vulnerability identifier: #VU15923
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-19039
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to obtain potentially sensitive information.

The vulnerability exists due to file exfiltration. A local attacker with Editor or Admin permissions can read any file that the Grafana process can read from the filesystem.


Affected software

Grafana
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
SUSE Linux
Red Hat Ceph Storage

How to mitigate CVE-2018-19039

The vulnerability has been fixed in the versions 4.6.5, 5.3.3.

Grafana - addressed in versions 4.6.5, 5.3.3

External References

Related Security Bulletins