Medium severity5.5NVD Advisory· Published Apr 29, 2020· Updated Jun 17, 2026
CVE-2020-12458
CVE-2020-12458
Description
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/grafana/grafanaGo | < 7.2.1 | 7.2.1 |
Affected products
29cpe:2.3:a:redhat:ceph_storage:3.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:ceph_storage:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:ceph_storage:4.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- Grafana/Grafanadescription
- osv-coords22 versionspkg:apk/chainguard/grafana-fips-11.6pkg:apk/chainguard/grafana-fips-12.1pkg:apk/chainguard/grafana-fips-12.2pkg:apk/chainguard/grafana-fips-12.3pkg:apk/chainguard/grafana-fips-12.4pkg:apk/chainguard/grafana-fips-13.0pkg:apk/chainguard/grafana-fips-13.1pkg:golang/github.com/grafana/grafanapkg:rpm/almalinux/grafana-azure-monitorpkg:rpm/almalinux/grafana-cloudwatchpkg:rpm/almalinux/grafana-graphitepkg:rpm/almalinux/grafana-influxdbpkg:rpm/almalinux/grafana-lokipkg:rpm/almalinux/grafana-mssqlpkg:rpm/almalinux/grafana-mysqlpkg:rpm/almalinux/grafana-opentsdbpkg:rpm/almalinux/grafana-postgrespkg:rpm/almalinux/grafana-prometheuspkg:rpm/almalinux/grafana-stackdriverpkg:bitnami/grafanapkg:rpm/almalinux/grafanapkg:rpm/almalinux/grafana-elasticsearch
< 0+ 21 more
- (no CPE)range: < 0
- (no CPE)range: < 12.1.10.01-r3
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 13.1.0-r0
- (no CPE)range: < 7.2.1
- (no CPE)range: < 6.7.4-3.el8
- (no CPE)range: < 6.7.4-3.el8
- (no CPE)range: < 6.7.4-3.el8
- (no CPE)range: < 6.7.4-3.el8
- (no CPE)range: < 6.7.4-3.el8
- (no CPE)range: < 6.7.4-3.el8
- (no CPE)range: < 6.7.4-3.el8
- (no CPE)range: < 6.7.4-3.el8
- (no CPE)range: < 6.7.4-3.el8
- (no CPE)range: < 6.7.4-3.el8
- (no CPE)range: < 6.7.4-3.el8
- (no CPE)range: < 6.7.4
- (no CPE)range: < 6.7.4-3.el8
- (no CPE)range: < 6.7.4-3.el8
Patches
Vulnerability mechanics
References
12- github.com/grafana/grafana/issues/8283nvdExploitIssue TrackingThird Party AdvisoryWEB
- access.redhat.com/security/cve/CVE-2020-12458nvdThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-3jq7-8ph8-63xmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-12458ghsaADVISORY
- security.netapp.com/advisory/ntap-20200518-0001/nvdThird Party Advisory
- github.com/grafana/grafana/commit/102448040d5132460e3b0013e03ebedec0677e00ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/CTQCKJZZYXMCSHJFZZ3YXEO5NUBANGZSghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/WEBCIEVSYIDDCA7FTRS2IFUOYLIQU34AghsaWEB
- security.netapp.com/advisory/ntap-20200518-0001ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTQCKJZZYXMCSHJFZZ3YXEO5NUBANGZS/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WEBCIEVSYIDDCA7FTRS2IFUOYLIQU34A/nvd
News mentions
0No linked articles in our index yet.