First published: Thu Apr 23 2020(Updated: )
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/grafana | <0:6.7.4-3.el8 | 0:6.7.4-3.el8 |
go/github.com/grafana/grafana | <7.2.1 | 7.2.1 |
Grafana Grafana | <=6.7.3 | |
Redhat Ceph Storage | =3.0 | |
Redhat Ceph Storage | =4.0 | |
Redhat Enterprise Linux | =8.0 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 |
Manually change the directory and files permissions to remove readable bits for others: # chmod 750 /var/lib/grafana # chmod 640 /var/lib/grafana/grafana.db # chown grafana:grafana /var/lib/grafana/grafana.db
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12458 is an information-disclosure vulnerability found in Grafana through version 6.7.3.
CVE-2020-12458 allows the world-readable permissions for the database directory and file in Grafana, which can expose sensitive information such as cleartext or encrypted datasource passwords.
CVE-2020-12458 has a severity rating of 6.2 (Medium).
To fix CVE-2020-12458, upgrade Grafana to version 6.7.4-3.el8 or higher.
You can find more information about CVE-2020-12458 at the following references: [link1], [link2], [link3].