MEDIUM5.5
GHSA-3jq7-8ph8-63xm
Grafana information disclosure
Quick fix
GHSA-3jq7-8ph8-63xm — github.com/grafana/grafana: upgrade to the fixed version with the command below.
go get github.com/grafana/grafana@v7.2.1Details
An information-disclosure flaw was found in Grafana. The database directory `/var/lib/grafana` and database file `/var/lib/grafana/grafana.db` are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/grafana/grafana
Introduced in:
0Fixed in: 7.2.1Fix
go get github.com/grafana/grafana@v7.2.1References
- https://nvd.nist.gov/vuln/detail/CVE-2020-12458[ADVISORY]
- https://github.com/grafana/grafana/issues/8283[WEB]
- https://github.com/grafana/grafana/commit/102448040d5132460e3b0013e03ebedec0677e00[WEB]
- https://access.redhat.com/security/cve/CVE-2020-12458[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=1827765[WEB]
- https://github.com/grafana/grafana[PACKAGE]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CTQCKJZZYXMCSHJFZZ3YXEO5NUBANGZS[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WEBCIEVSYIDDCA7FTRS2IFUOYLIQU34A[WEB]
- https://security.netapp.com/advisory/ntap-20200518-0001[WEB]