CVE-2020-12458

Aliases:GHSA-3jq7-8ph8-63xmBIT-grafana-2020-12458GO-2024-2513CGA-22vj-c5vj-pjw6CGA-2prm-fpgq-x7p9CGA-2w8g-mqg2-g64rCGA-34m5-cm99-hq23CGA-379g-p65m-xwcrCGA-5mj7-qvhp-m3j4CGA-63fw-hc85-cmgvCGA-6q7g-54m4-8mw2CGA-6wpp-jg9p-7jrmCGA-7683-jc3j-gcg5CGA-79qc-2gq8-xqr9CGA-85v7-xc8p-g5mrCGA-8vhh-jp9p-p822CGA-cm4p-475h-qw23CGA-g8w5-mp3j-j8ppCGA-ggq3-jcr6-pgjrCGA-gjqc-j964-h96qCGA-grv7-8wv2-j86jCGA-hwcj-4r3p-wp5hCGA-jf8c-2pgw-88p2CGA-jr3g-rwgh-63h6CGA-mmmf-8x8q-hg7vCGA-p2gh-hf6r-qw4fCGA-p6v5-q5mf-2gmhCGA-pc5m-q9h8-fv2rCGA-pg29-h6qg-6wx5CGA-r5j7-pm8x-gg82CGA-rfq2-qph4-2p8xCGA-rm33-97pp-25f3CGA-rvqc-q7v9-5h9fCGA-v6fj-jq7p-hpwcCGA-vr97-p34v-6423CGA-vvwf-6mwc-r69fCGA-w69x-77f6-379hCGA-w9hr-fj8v-qcc4CGA-wc82-5hfv-c465CGA-wpg8-8wjf-6gv4CGA-wv6h-hx45-m8crCGA-x32g-82mg-8jx8CGA-xc3g-8jhr-9mfg
Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 29 Apr 2020, 15:57
Last modified:04 Aug 2024, 11:56

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.47% LOW
0% probability +0.40%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

29 Apr 2020, 15:57
Published
Vulnerability first disclosed
04 Aug 2024, 11:56
Last Modified
Vulnerability information updated

Description

An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).

CVSS Metrics

  • v4.0HIGHScore: 7.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • v2.0LOWScore: 2.1AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.47% Percentile: 40%

Techniques & Countermeasures

  • CWE-732Incorrect Permission Assignment for Critical Resource

    The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Affected Systems

  • chainguardgrafana-fips-11.6

    < 0

  • chainguardgrafana-fips-12.0

    < 12.0.10-r6

  • chainguardgrafana-fips-12.1

    < 12.1.10.01-r3

  • chainguardgrafana-fips-12.2

    < 0

  • chainguardgrafana-fips-12.3

    < 0

  • chainguardgrafana-fips-12.4

    < 0

  • chainguardgrafana-fips-13.0

    < 0

  • chainguardgrafana-fips-13.1

    < 13.1.0-r0

  • fedoraprojectfedora

    31 | 32

  • github.com/grafanagrafana

    all | < 7.2.1

  • grafanagrafana

    ≤ 6.7.3

  • redhatceph_storage

    3.0 | 4.0

  • redhatenterprise_linux

    8.0

References (13)