Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
https://security.netapp.com/advisory/ntap-20190416-0004/
https://community.grafana.com/t/grafana-5-3-3-and-4-6-5-security-update/11961
https://access.redhat.com/errata/RHSA-2019:0911
https://access.redhat.com/errata/RHSA-2019:0747
http://www.securityfocus.com/bid/105994
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00009.html