Impact
The vulnerability involves the Grafana Global Hub application exposing database connection credentials directly through an environment variable when configuring the database connection string. The embedded credentials are visible in plaintext as the application reads the variable without further protection, which constitutes clear‑text storage of sensitive information (CWE-312) and could lead to disclosure of database credentials.
Affected Systems
The flaw affects Grafana Global Hub. No specific version information is available from public sources, so administrators should determine the installed edition and version of Grafana Global Hub and consult vendor documentation for remedies that address credential handling in environment variables.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate severity assessment. EPSS data is not available, so the likelihood of exploitation cannot be quantified. The flaw is not listed in CISA’s KEV catalog. Based on the title, the most likely attack vector requires local access to the process environment or to logs that capture the environment variable. An attacker with such access could read the embedded credentials and potentially use them to reach the database.
OpenCVE Enrichment