CVE-2018-19039
Advisory lineage Upstream: 0 Downstream: 12
Modified
Published: 13 Dec 2018, 19:00
Last modified:05 Aug 2024, 11:23
Vulnerability Summary
Overall Risk (default)
medium
28/100 CVSS Score
6.5 MEDIUM
v3.0 (nvd)
EPSS Score
9.22% LOW
9% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
13 Dec 2018, 19:00
Published
Vulnerability first disclosed
05 Aug 2024, 11:23
Last Modified
Vulnerability information updated
Description
Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
CVSS Metrics
- v3.0•MEDIUM•Score: 6.5CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- v2.0•MEDIUM•Score: 4AV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 9.22%• Percentile: 93%
Techniques & Countermeasures
- CWE-200•Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Affected Systems
- grafana•grafana
< 4.6.5 | ≥ 5.0.0, < 5.3.3
- netapp•active_iq_performance_analytics_services
na
- netapp•storagegrid_webscale_nas_bridge
na
- redhat•ceph_storage
3.0
- redhat•enterprise_linux_desktop
7.0
- redhat•enterprise_linux_server
7.0
- redhat•enterprise_linux_workstation
7.0
References (7)
- http://www.securityfocus.com/bid/105994
- https://community.grafana.com/t/grafana-5-3-3-and-4-6-5-security-update/11961
- https://www.percona.com/blog/2018/11/20/how-cve-2018-19039-affects-percona-monitoring-and-management/
- https://access.redhat.com/errata/RHSA-2019:0747
- https://security.netapp.com/advisory/ntap-20190416-0004/
- https://access.redhat.com/errata/RHSA-2019:0911
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00009.html