CVE-2020-12458

An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).

Date published : 2020-04-29

https://access.redhat.com/security/cve/CVE-2020-12458

https://security.netapp.com/advisory/ntap-20200518-0001/