CVE-2020-12459
29.04.2020, 16:15
In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| grafana | grafana | 6.0.0 ≤ 𝑥 ≤ 6.3.6 |
𝑥
= Vulnerable software versions
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| grafana |
| ||
| grafana-azure-monitor |
| ||
| grafana-cloudwatch |
| ||
| grafana-elasticsearch |
| ||
| grafana-graphite |
| ||
| grafana-influxdb |
| ||
| grafana-loki |
| ||
| grafana-mssql |
| ||
| grafana-mysql |
| ||
| grafana-opentsdb |
| ||
| grafana-postgres |
| ||
| grafana-prometheus |
| ||
| grafana-stackdriver |
|
Common Weakness Enumeration
References