CVE-2018-19039
published 2018-12-13CVE-2018-19039: Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
PriorityP340medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
7.28%
93.6th percentile
Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| grafana | grafana | < 4.6.5 | 4.6.5 |
| grafana | grafana | >= 5.0.0 < 5.3.3 | 5.3.3 |
| redhat | ceph_storage | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7vqc-8389-rvvr: Grafana before 4
ghsa_unreviewed·2022-05-13
CVE-2018-19039 [MEDIUM] CWE-200 GHSA-7vqc-8389-rvvr: Grafana before 4
Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
OSV
CVE-2018-19039: Grafana before 4
osv·2018-12-13·CVSS 6.5
CVE-2018-19039 [MEDIUM] CVE-2018-19039: Grafana before 4
Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
Red Hat
grafana: File exfiltration
vendor_redhat·2018-11-13·CVSS 6.5
CVE-2018-19039 [MEDIUM] CWE-200 grafana: File exfiltration
grafana: File exfiltration
Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
A security issue was found that could allow any users with Editor or Admin permissions in Grafana to read any file that the Grafana process can read from the filesystem. However, in order to exploit this issue you would need to be logged in to the system as a legitimate user with Editor or Admin permissions.
Package: openshift3/grafana (Red Hat OpenShift Container Platform 3.11) - Affected
Package: openshift4/ose-grafana (Red Hat OpenShift Container Platform 4) - Not affected
Package: grafana (Red Hat OpenStack Platform 8 (Liberty) Operational Tools) - Will not fix
Package: grafana (Red Hat OpenStack Platform 9 (Mita
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00009.htmlhttp://www.securityfocus.com/bid/105994https://access.redhat.com/errata/RHSA-2019:0747https://access.redhat.com/errata/RHSA-2019:0911https://community.grafana.com/t/grafana-5-3-3-and-4-6-5-security-update/11961https://security.netapp.com/advisory/ntap-20190416-0004/https://www.percona.com/blog/2018/11/20/how-cve-2018-19039-affects-percona-monitoring-and-management/http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00009.htmlhttp://www.securityfocus.com/bid/105994https://access.redhat.com/errata/RHSA-2019:0747https://access.redhat.com/errata/RHSA-2019:0911https://community.grafana.com/t/grafana-5-3-3-and-4-6-5-security-update/11961https://security.netapp.com/advisory/ntap-20190416-0004/https://www.percona.com/blog/2018/11/20/how-cve-2018-19039-affects-percona-monitoring-and-management/
2018-12-13
Published