github.com
https://github.com/grafana/grafana CVE-2025-3454
MEDIUM
Grafana's datasource proxy API allows authorization checks to be bypassed
Record summary
CVE-2025-3454 has a selected CVSS score of 5.0 (medium).
Description
This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 2, 2025 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
GrafanaBrowse Grafana / Grafana | CVE List | 11.6.0 to < 11.6.0+security-01 | affected |
| 11.5.0 to < 11.5.3+security-01 | affected | ||
| 11.4.0 to < 11.4.3+security-01 | affected | ||
| 11.3.0 to < 11.3.5+security-01 | affected | ||
| 11.2.0 to < 11.2.8+security-01 | affected | ||
| 10.4.0 to < 10.4.17+security-01 | affected | ||
Grafana EnterpriseBrowse Grafana / Grafana Enterprise | CVE List | 11.6.0 to < 11.6.0+security-01 | affected |
| 11.5.0 to < 11.5.3+security-01 | affected | ||
| 11.4.0 to < 11.4.3+security-01 | affected | ||
| 11.3.0 to < 11.3.5+security-01 | affected | ||
| 11.2.0 to < 11.2.8+security-01 | affected | ||
| 10.4.0 to < 10.4.17+security-01 | affected | ||
github.com/grafana/grafanaBrowse Go / github.com/grafana/grafana | GitHub Advisory | 0.0.0-20210414170620-dadccdda06e6 to < 0.0.0-20250424191517-1f707d16ed5d · Fixed in 0.0.0-20250424191517-1f707d16ed5d | affected |
References
5github.com
https://github.com/grafana/grafana/blob/be8d153dc33734caba4f617ff571d18253e68fa0/CHANGELOG.md grafana.com
https://grafana.com/blog/2025/04/22/grafana-security-release-medium-and-high-severity-fixes-for-cve-2025-3260-cve-2025-2703-cve-2025-3454 grafana.com
https://grafana.com/security/security-advisories/cve-2025-3454 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-3454