CVE-2019-19499: Infoleak
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.
Other sources
Grafana has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19499?
The severity of CVE-2019-19499 is medium.
How can the Grafana Arbitrary File Read vulnerability (CVE-2019-19499) be exploited?
The Grafana Arbitrary File Read vulnerability (CVE-2019-19499) can be exploited by an authenticated attacker with privileges to modify data source configurations.
What software versions are affected by CVE-2019-19499?
Grafana versions <= 6.4.3 are affected by CVE-2019-19499.
How can I fix CVE-2019-19499?
To fix CVE-2019-19499, update Grafana to version 6.7.4-3.el8 or later.
Where can I find more information about CVE-2019-19499?
You can find more information about CVE-2019-19499 at the following references: [CVE-2019-19499](https://www.cve.org/CVERecord?id=CVE-2019-19499), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-19499), [PTSecurity](https://swarm.ptsecurity.com/grafana-6-4-3-arbitrary-file-read/), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1873615), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2020:4682).