Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 13, 2018 |
| Centos_linux | — | Upgrade libradosstriper1Upgrade ceph-baseUpgrade librgw2Upgrade python-rgwUpgrade ceph-ansibleUpgrade libcephfs2Upgrade grafanaUpgrade ceph-selinuxUpgrade librgw2-develUpgrade libcephfs-develUpgrade librados-develUpgrade python-cephfsUpgrade librbd-develUpgrade ceph-mdsUpgrade rbd-mirrorUpgrade librgw-develUpgrade ceph-radosgwUpgrade ceph-commonUpgrade ceph-fuseUpgrade ceph-debuginfoUpgrade libcephfs1Upgrade libcephfs1-devel | Aug 28, 2019 | Dec 13, 2018 |
| Redhat_linux | — | Upgrade libcephfs1Upgrade libcephfs2Upgrade librgw-develUpgrade librados-develUpgrade ceph-commonUpgrade grafanaUpgrade ceph-baseUpgrade librgw2-develUpgrade libcephfs1-develUpgrade libcephfs-develUpgrade ceph-selinuxUpgrade librbd-develUpgrade ceph-ansibleUpgrade ceph-debuginfoUpgrade ceph-fuseUpgrade python-rgwUpgrade libradosstriper1Upgrade python-cephfsUpgrade librgw2Upgrade rbd-mirrorUpgrade ceph-mdsUpgrade ceph-radosgw | Apr 15, 2019 | Dec 13, 2018 |
| Suse | — | Upgrade grafana | Feb 4, 2022 | Dec 13, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Dec 13, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub