CVE-2020-12459 — Incorrect Permission Assignment in Grafana Grafana
CWE-732 — Incorrect Permission AssignmentCWE-200 — Sensitive Information Exposure10 documents6 sources
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 74.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 29
Latest updateJul 2
Description
In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages2 packages
Also affects: Fedora 31, 32
Patches
🔴Vulnerability Details
4📋Vendor Advisories
1Red Hat
▶
💬Community
4Bugzilla▶
CVE-2020-12459 grafana: information disclosure through world-readable grafana configuration files [fedora-all]↗2020-04-30
Bugzilla▶
CVE-2020-12459 grafana: information disclosure through world-readable grafana configuration files [fedora-all]↗2020-04-30
Bugzilla▶
CVE-2020-12459 grafana: information disclosure through world-readable grafana configuration files↗2020-04-30