CVE-2025-3454
Published: Jun 2, 2025
Modified: Jun 2, 2025
CVSS v3.1
5.0
Description
This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.
| Vendor | Product | Versions |
|---|---|---|
Grafana | Grafana | affected 11.6.0 - < 11.6.0+security-01affected 11.5.0 - < 11.5.3+security-01affected 11.4.0 - < 11.4.3+security-01affected 11.3.0 - < 11.3.5+security-01affected 11.2.0 - < 11.2.8+security-01+1 more versions |
Grafana | Grafana Enterprise | affected 11.6.0 - < 11.6.0+security-01affected 11.5.0 - < 11.5.3+security-01affected 11.4.0 - < 11.4.3+security-01affected 11.3.0 - < 11.3.5+security-01affected 11.2.0 - < 11.2.8+security-01+1 more versions |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now