QID 997071
Date Published: 2024-02-07
QID 997071: GO (Go) Security Update for github.com/grafana/grafana (GHSA-m25m-5778-fm22)
In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-m25m-5778-fm22 for updates and patch information.
Vendor References
- GHSA-m25m-5778-fm22 -
github.com/advisories/GHSA-m25m-5778-fm22
CVEs related to QID 997071
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-m25m-5778-fm22 | github.com/grafana/grafana |
|