CVE-2018-19039 is a medium-severity vulnerability affecting Grafana versions prior to 4.6.5 and 5.x before 5.3.3, as well as related products from NetApp and Red Hat. This flaw allows authenticated users with Editor or Admin permissions to read arbitrary files on the system. The vulnerability has a CVSS score of 6.5, indicating a low attack complexity and no user interaction required, with a high impact on confidentiality. While there is no evidence of active exploitation, public exploit code, or Metasploit modules, the vulnerability has garnered some community discussion and media coverage, suggesting it has received a moderate level of attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.6.5CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.3.3CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:redhat:ceph_storage:3.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.