CVE-2020-12458: Medium severity grafana labs grafana oss and enterprise vulnerability
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).
Other sources
An information-disclosure flaw was found in Grafana. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).
— GitHub
An information-disclosure flaw was found in the way Grafana set permissions for the database directory and file. This flaw allows a local attacker access to potentially sensitive information such as cleartext or encrypted datasource passwords from /var/lib/grafana/grafana.db.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-12458?
CVE-2020-12458 is an information-disclosure vulnerability found in Grafana through version 6.7.3.
How does CVE-2020-12458 affect Grafana?
CVE-2020-12458 allows the world-readable permissions for the database directory and file in Grafana, which can expose sensitive information such as cleartext or encrypted datasource passwords.
How severe is CVE-2020-12458?
CVE-2020-12458 has a severity rating of 6.2 (Medium).
How can I fix CVE-2020-12458?
To fix CVE-2020-12458, upgrade Grafana to version 6.7.4-3.el8 or higher.
Where can I find more information about CVE-2020-12458?
You can find more information about CVE-2020-12458 at the following references: [link1], [link2], [link3].