CVE-2025-3415
Grafana's insecure DingDing Alert integration exposes sensitive information
Record summary
CVE-2025-3415 has a selected CVSS score of 4.3 (medium); EIP currently links 1 Nuclei template.
Description
Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5+security-01, 11.6.2+security-01 and 12.0.1+security-01
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 7, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 17, 2025 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
GrafanaBrowse Grafana / GrafanaDefault status: unaffected | CVE List | 10.4.x to < 10.4.19+security-01 | affected |
| 11.2.x to < 11.2.10+security-01 | affected | ||
| 11.3.x to < 11.3.7+security-01 | affected | ||
| 11.4.x to < 11.4.5+security-01 | affected | ||
| 11.5.x to < 11.5.5+security-01 | affected | ||
| 11.6.x to < 11.6.2+security-01 | affected | ||
| 12.0.x to < 12.0.1+security-01 | affected | ||
| VulnCheck | Version data not supplied | ||
github.com/grafana/grafanaBrowse Go / github.com/grafana/grafana | GitHub Advisory | Before 1.9.2-0.20250514160932-04111e9f2afd · Fixed in 1.9.2-0.20250514160932-04111e9f2afd | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMGrafana - Exposes DingDing API Keys
An incident occurred where the DingDing alerting integration URL was inadvertently exposed to viewers due to a setting oversight in versions below or equals to 12.0.1.
Impact
Viewers can access DingDing alerting integration URLs containing access tokens through the alertmanager API, potentially enabling unauthorized message delivery and notification manipulation.
Remediation
Upgrade to Grafana version 12.0.2 or later that properly restricts access to DingDing integration settings.
Source: ProjectDiscovery