Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 13, 2018 |
| Centos_linux | — | Upgrade ceph-radosgwUpgrade libcephfs1-develUpgrade ceph-debuginfoUpgrade librados-develUpgrade ceph-fuseUpgrade python-cephfsUpgrade librgw2-develUpgrade libcephfs1Upgrade librbd-develUpgrade librgw-develUpgrade rbd-mirrorUpgrade ceph-mdsUpgrade ceph-commonUpgrade libcephfs-develUpgrade ceph-baseUpgrade ceph-selinuxUpgrade grafanaUpgrade ceph-ansibleUpgrade libradosstriper1Upgrade librgw2Upgrade python-rgwUpgrade libcephfs2 | Aug 28, 2019 | Dec 13, 2018 |
| Redhat_linux | — | Upgrade librgw2-develUpgrade ceph-commonUpgrade ceph-baseUpgrade libcephfs1Upgrade librados-develUpgrade libcephfs2Upgrade libcephfs-develUpgrade libcephfs1-develUpgrade librgw-develUpgrade grafanaUpgrade librgw2Upgrade ceph-debuginfoUpgrade ceph-selinuxUpgrade libradosstriper1Upgrade python-cephfsUpgrade ceph-fuseUpgrade rbd-mirrorUpgrade ceph-ansibleUpgrade librbd-develUpgrade ceph-mdsUpgrade python-rgwUpgrade ceph-radosgw | Apr 15, 2019 | Dec 13, 2018 |
| Suse | — | Upgrade grafana | Feb 4, 2022 | Dec 13, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Dec 13, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub