Description
In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.
Remediation
References
Related Vulnerabilities
WordPress Plugin NEX-Forms-Ultimate Form builder Multiple SQL Injection Vulnerabilities (4.0)
WordPress Plugin Work The Flow File Upload Arbitrary File Upload (2.5.2)
Chart.js Improper Input Validation Vulnerability (CVE-2020-7746)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-1950)
WordPress Use of Insufficiently Random Values Vulnerability (CVE-2017-17091)