[CVE-2019-19499] Grafana 6.4.3 Arbitrary File Read
swarm.ptsecurity.com | research | CVE-2019-19499 | #vulnerability-research | #cve | #mysql | #grafana | #file-read
Summary
CVE-2019-19499 in Grafana 6.4.3: a rogue MySQL data source answers LOCAL INFILE requests to exfiltrate arbitrary files from the Grafana host, turning the 'add a data source' feature into an authenticated arbitrary file read.
- Published
- Collected
Skip to content