4
CVSSv2

CVE-2018-19039

Published: 13/12/2018 Updated: 04/10/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Grafana prior to 4.6.5 and 5.x prior to 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

grafana grafana

redhat enterprise linux workstation 7.0

redhat ceph storage 3.0

redhat enterprise linux desktop 7.0

redhat enterprise linux server 7.0

netapp active iq performance analytics services -

netapp storagegrid webscale nas bridge -

Vendor Advisories

Synopsis Moderate: Red Hat Ceph Storage 25 security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for ceph and grafana is now available for Red Hat Ceph Storage 25 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Mo ...
Synopsis Moderate: Red Hat Ceph Storage 32 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat Ceph Storage 32Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring ...
A security issue was found that could allow any users with Editor or Admin permissions in Grafana to read any file that the Grafana process can read from the filesystem However, in order to exploit this issue you would need to be logged in to the system as a legitimate user with Editor or Admin permissions ...
Al security issue has been found in grafana before 533, that could allow any users with Editor or Admin permissions in Grafana to read any file that the Grafana process can read from the filesystem Note, that in order to exploit this you would need to be logged in to the system as a legitimate user with Editor or Admin permissions ...