CVE-2018-19039: Infoleak
A security issue was found that could allow any users with Editor or Admin permissions in Grafana to read any file that the Grafana process can read from the filesystem. Note, that in order to exploit this you would need to be logged in to the system as a legitimate user with Editor or Admin permissions.
External References:
https://community.grafana.com/t/grafana-5-3-3-and-4-6-5-security-update/11961
Other sources
Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Grafana vulnerability?
The vulnerability ID for this Grafana vulnerability is CVE-2018-19039.
What is the severity level of CVE-2018-19039?
The severity level of CVE-2018-19039 is medium.
How can remote authenticated users exploit CVE-2018-19039?
Remote authenticated users can exploit CVE-2018-19039 by leveraging Editor or Admin permissions to read arbitrary files.
Which versions of Grafana are affected by CVE-2018-19039?
Grafana versions before 4.6.5 and 5.x before 5.3.3 are affected by CVE-2018-19039.
How can I fix CVE-2018-19039?
To fix CVE-2018-19039, update Grafana to version 4.6.5 or 5.3.3.