MEDIUM6.5
GHSA-4pwp-cx67-5cpx
Grafana Arbitrary File Read
Quick fix
GHSA-4pwp-cx67-5cpx — github.com/grafana/grafana: upgrade to the fixed version with the command below.
go get github.com/grafana/grafana@v6.4.4Details
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/grafana/grafana
Introduced in:
0Fixed in: 6.4.4Fix
go get github.com/grafana/grafana@v6.4.4References
- https://nvd.nist.gov/vuln/detail/CVE-2019-19499[ADVISORY]
- https://github.com/grafana/grafana/pull/20192[WEB]
- https://github.com/grafana/grafana/commit/19dbd27c5caa1a160bd5854b65a4e1fe2a8a4f00[WEB]
- https://github.com/grafana/grafana[PACKAGE]
- https://github.com/grafana/grafana/blob/master/CHANGELOG.md#644-2019-11-06[WEB]
- https://security.netapp.com/advisory/ntap-20200918-0003[WEB]