CVE-2020-12459

Aliases:GHSA-m25m-5778-fm22BIT-grafana-2020-12459GO-2024-2519CGA-2785-gm8c-7rc2CGA-2vrh-4m7v-g5h6CGA-37fq-32hm-f4fqCGA-37g9-2hgc-9jwrCGA-4c64-pwvr-6cv4CGA-4p4c-mh8h-88q7CGA-4wrr-rxpx-vfwwCGA-5g68-5jxh-2fwqCGA-66q3-235q-8hfwCGA-6v6x-mccf-x86rCGA-6w76-mqcv-4h2jCGA-787q-w45w-rxcrCGA-86rg-j6g5-8qfxCGA-8qpp-95q8-xrrwCGA-8v4q-fcvf-g7p4CGA-92cq-qqh8-fj46CGA-9r9w-q9c9-5r39CGA-cc93-wmcp-x9cgCGA-g2wm-7c5r-4pfwCGA-gg6m-4r48-wprwCGA-gvwx-rgjf-c2m4CGA-gw6c-rjj8-xjxhCGA-h2vh-3g79-pprcCGA-h4jh-mgr9-373fCGA-hx4w-rcrm-crffCGA-j8hp-97j4-fvqhCGA-jmpc-rjcx-g55cCGA-m327-rhm6-mqvjCGA-mv37-4v27-4rf5CGA-mxfj-8hwp-2hfhCGA-p536-gc79-j55cCGA-pf5p-qq93-xcr4CGA-pf7c-87jp-g93vCGA-q59q-85q3-h3xrCGA-qr9p-chq7-g29hCGA-r664-qqh9-rxhmCGA-rf88-c2x3-3979CGA-vfx4-p34c-6pwhCGA-vv89-fg4g-x37mCGA-w5x2-4r4v-885x
Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 29 Apr 2020, 15:56
Last modified:04 Aug 2024, 11:56

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.32% LOW
0% probability +0.23%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

29 Apr 2020, 15:56
Published
Vulnerability first disclosed
04 Aug 2024, 11:56
Last Modified
Vulnerability information updated

Description

In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.

CVSS Metrics

  • v4.0HIGHScore: 7.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • v2.0LOWScore: 2.1AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.32% Percentile: 25%

Techniques & Countermeasures

  • CWE-732Incorrect Permission Assignment for Critical Resource

    The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Affected Systems

  • chainguardgrafana-fips-11.6

    < 0

  • chainguardgrafana-fips-12.0

    < 0

  • chainguardgrafana-fips-12.1

    < 0

  • chainguardgrafana-fips-12.2

    < 0

  • chainguardgrafana-fips-12.3

    < 0

  • chainguardgrafana-fips-12.4

    < 0

  • chainguardgrafana-fips-13.0

    < 0

  • chainguardgrafana-fips-13.1

    < 0

  • fedoraprojectfedora

    31 | 32

  • github.com/grafanagrafana

    all | ≥ 6.0.0-beta1, < 7.2.1

  • grafanagrafana

    ≥ 6.0.0, ≤ 6.3.6

References (15)