| Vulnerability Name: | CVE-2019-19499 (CCN-187495) | ||||||||||||||||||
| Assigned: | 2019-10-28 | ||||||||||||||||||
| Published: | 2019-10-28 | ||||||||||||||||||
| Updated: | 2022-04-28 | ||||||||||||||||||
| Summary: | Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations. | ||||||||||||||||||
| CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:R)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:R)
5.7 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:R)
| ||||||||||||||||||
| CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||||||||||||||
| Vulnerability Type: | CWE-89 CWE-200 | ||||||||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2019-19499 Source: XF Type: UNKNOWN grafana-cve201919499-info-disc(187495) Source: CCN Type: Grafana GIT Repository Grafana: The open observability platform | Grafana Labs Source: CONFIRM Type: Third Party Advisory https://security.netapp.com/advisory/ntap-20200918-0003/ Source: CCN Type: Positive Technologies Web site Grafana <= 6.4.3 Arbitrary File Read Source: MISC Type: Exploit, Third Party Advisory https://swarm.ptsecurity.com/grafana-6-4-3-arbitrary-file-read/ Source: CCN Type: WhiteSource Vulnerability Database CVE-2019-19499 | ||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||
| Oval Definitions | |||||||||||||||||||
| |||||||||||||||||||
| BACK | |||||||||||||||||||