CVE-2020-12459

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/04/2020
Last modified:
07/11/2023

Description

In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* 6.0.0 (including) 6.3.6 (including)
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*