Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 13, 2018 |
| Centos_linux | — | Upgrade libcephfs1Upgrade libcephfs1-develUpgrade librados-develUpgrade ceph-mdsUpgrade libcephfs-develUpgrade python-cephfsUpgrade ceph-commonUpgrade ceph-debuginfoUpgrade librgw-develUpgrade ceph-fuseUpgrade ceph-radosgwUpgrade librbd-develUpgrade librgw2-develUpgrade rbd-mirrorUpgrade ceph-ansibleUpgrade grafanaUpgrade libradosstriper1Upgrade ceph-baseUpgrade librgw2Upgrade python-rgwUpgrade libcephfs2Upgrade ceph-selinux | Aug 28, 2019 | Dec 13, 2018 |
| Redhat_linux | — | Upgrade librgw2Upgrade rbd-mirrorUpgrade ceph-ansibleUpgrade libradosstriper1Upgrade python-cephfsUpgrade ceph-selinuxUpgrade ceph-mdsUpgrade ceph-fuseUpgrade python-rgwUpgrade librbd-develUpgrade ceph-radosgwUpgrade ceph-debuginfoUpgrade grafanaUpgrade librgw2-develUpgrade libcephfs2Upgrade libcephfs1-develUpgrade librgw-develUpgrade libcephfs-develUpgrade librados-develUpgrade ceph-commonUpgrade ceph-baseUpgrade libcephfs1 | Apr 15, 2019 | Dec 13, 2018 |
| Suse | — | Upgrade grafana | Feb 4, 2022 | Dec 13, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Dec 13, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub