CVE-2018-19039: Grafana
Medium severity, CVSS 6.5. EPSS: 7.3% chance of exploitation in the next 30 days.
Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
Affected products
- Grafana Grafana: before 4.6.5 (fixed in 4.6.5); from 5.0.0, before 5.3.3 (fixed in 5.3.3)
- Netapp Active Iq Performance Analytics Services: affected versions not specified
- Netapp Storagegrid Webscale NAS Bridge: affected versions not specified
- Red Hat Ceph Storage: version 3.0 only
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
Published 2018-12-13. Last modified 2026-06-17.