Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
2018-12-13T19:29:00.403
2024-11-21T03:57:12.097
Modified
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | grafana | grafana | < 4.6.5 | Yes |
Application | grafana | grafana | < 5.3.3 | Yes |
Application | redhat | ceph_storage | 3.0 | Yes |
Operating System | redhat | enterprise_linux_desktop | 7.0 | Yes |
Operating System | redhat | enterprise_linux_server | 7.0 | Yes |
Operating System | redhat | enterprise_linux_workstation | 7.0 | Yes |
Application | netapp | active_iq_performance_analytics_services | - | Yes |
Application | netapp | storagegrid_webscale_nas_bridge | - | Yes |