Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2019-19499] Grafana 6.4.3 Arbitrary File Read

Summary

CVE-2019-19499 in Grafana 6.4.3: a rogue MySQL data source answers LOCAL INFILE requests to exfiltrate arbitrary files from the Grafana host, turning the 'add a data source' feature into an authenticated arbitrary file read.
Published
Collected

original ↗

Related coverage

back