Description
A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.
Remediation
References
Related Vulnerabilities
TYPO3 Improper Authentication Vulnerability (CVE-2014-3944)
silverstripeCMS Credentials Management Errors Vulnerability (CVE-2010-5080)
Drupal Other Vulnerability (CVE-2006-5477)
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-4613)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-1686)