Unprotected storage of credentials in Grafana - CVE-2019-15635
Published: September 20, 2019
Grafana
Detailed vulnerability description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to an error in encrypt-datasource-passwords data migration command that failed to encrypt user credentials for various data sources. A local user can view migration settings and reveal database credentials.
Note, this vulnerability can be exploited via Grafana web UI by pressing the "Save and test" button within a data source's settings menu.