Total vulnerabilities in the database
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).
Software | From | Fixed in |
---|---|---|
grafana / grafana | - | 6.7.3.x |
redhat / ceph_storage | 3.0 | 3.0.x |
redhat / enterprise_linux | 8.0 | 8.0.x |
redhat / ceph_storage | 4.0 | 4.0.x |
fedoraproject / fedora | 31 | 31.x |
fedoraproject / fedora | 32 | 32.x |