{"id":"CVE-2019-19499","aliases":["GHSA-4pwp-cx67-5cpx","GO-2024-2661"],"title":"Grafana Arbitrary File Read","summary":"Grafana Arbitrary File Read","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P","vendor":"grafana","product":"github.com/grafana/grafana","ecosystem":"go","affected":["github.com/grafana/grafana < 6.4.4"],"patched":["github.com/grafana/grafana 6.4.4"],"published":"2024-01-31","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:04.742754798Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-4pwp-cx67-5cpx","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-19499"},{"url":"https://github.com/grafana/grafana/pull/20192"},{"url":"https://github.com/grafana/grafana/commit/19dbd27c5caa1a160bd5854b65a4e1fe2a8a4f00"},{"url":"https://github.com/grafana/grafana"},{"url":"https://github.com/grafana/grafana/blob/master/CHANGELOG.md#644-2019-11-06"},{"url":"https://security.netapp.com/advisory/ntap-20200918-0003"}],"tags":["osv","go"],"epss":0.03621,"epssPercentile":0.89015,"ingestedAt":"2026-09-12T03:13:01.753Z","slug":"CVE-2019-19499","body":"## Overview\n\nGrafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.\n\n## Affected packages\n\n- `github.com/grafana/grafana < 6.4.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/grafana/grafana 6.4.4`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.7,"exploitation":0,"ransomware":0},"changes":[]}