Unprotected storage of credentials in Grafana - CVE-2019-15635
Published: September 20, 2019
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to an error in encrypt-datasource-passwords data migration command that failed to encrypt user credentials for various data sources. A local user can view migration settings and reveal database credentials.
Note, this vulnerability can be exploited via Grafana web UI by pressing the "Save and test" button within a data source's settings menu.
Affected software
Gentoo Linux
Amazon Linux AMI
Opensuse