QID 997068
Date Published: 2024-02-02
QID 997068: GO (Go) Security Update for github.com/grafana/grafana (GHSA-3jq7-8ph8-63xm)
An information-disclosure flaw was found in Grafana. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-3jq7-8ph8-63xm for updates and patch information.
Vendor References
- GHSA-3jq7-8ph8-63xm -
github.com/advisories/GHSA-3jq7-8ph8-63xm
CVEs related to QID 997068
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3jq7-8ph8-63xm | github.com/grafana/grafana |
|