Description
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).
Remediation
References
Related Vulnerabilities
WordPress Plugin GS Insever Portfolio Cross-Site Scripting (1.4.4)
Contao Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2019-10641)
Liferay Portal Improper Authentication Vulnerability (CVE-2021-29047)
WordPress Plugin CataBlog 'category' Parameter Cross-Site Scripting (1.6.2)