{"schema_version":"1.7.3","id":"GO-2024-2661","published":"2024-03-28T17:12:27Z","modified":"2026-06-19T18:29:27.740922375Z","aliases":["CVE-2019-19499","GHSA-4pwp-cx67-5cpx"],"related":["CGA-9fr5-rmwh-3542"],"summary":"Arbitrary file read in github.com/grafana/grafana","details":"An authenticated attacker that has privileges to modify the data source configurations can read arbitrary files.","affected":[{"package":{"name":"github.com/grafana/grafana","ecosystem":"Go","purl":"pkg:golang/github.com/grafana/grafana"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"ecosystem_specific":{"custom_ranges":[{"events":[{"introduced":"0"},{"fixed":"6.4.4"}],"type":"ECOSYSTEM"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2024-2661.json"}}],"references":[{"type":"FIX","url":"https://github.com/grafana/grafana/pull/20192"},{"type":"WEB","url":"https://github.com/grafana/grafana/blob/master/CHANGELOG.md#644-2019-11-06"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20200918-0003"},{"type":"WEB","url":"https://swarm.ptsecurity.com/grafana-6-4-3-arbitrary-file-read"}],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2024-2661"}}