SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-19039

Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.

MEDIUM 6.5EPSS 7.28%

Does this matter?

Lower severity and a low EPSS score (7.28%). Track it; it rarely justifies an emergency change on its own.

Description

Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
7.28% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
grafana/grafana · redhat/ceph storage · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation · netapp/active iq performance analytics services · netapp/storagegrid webscale nas bridge
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.