2.1
CVSSv2

CVE-2020-12458

Published: 29/04/2020 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An information-disclosure flaw was found in Grafana up to and including 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

grafana grafana

redhat ceph storage 3.0

redhat enterprise linux 8.0

redhat ceph storage 4.0

fedoraproject fedora 31

fedoraproject fedora 32

Vendor Advisories

Synopsis Moderate: grafana security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for grafana is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring Sy ...
Multiple vulnerabilities have been found in Hitachi Ops Center Analyzer viewpoint CVE-2020-11110, CVE-2020-12245, CVE-2020-12458, CVE-2020-13379, CVE-2020-13430 Affected products and versions are listed below Please upgrade your version to the appropriate version ...