CVE-2025-3717
LOWGrafana Snowflake Datasource Plugin <1.14.1 - Info Disclosure
Title source: llmDescription
When using the Grafana Snowflake Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, it could result in the wrong user identifier being used, and information for which the viewer is not authorized being returned. This issue affects Grafana Snowflake Datasource Plugin: from 1.5.0 before 1.14.1.
References (1)
Core 1
Core References
Various Sources
https://grafana.com/security/security-advisories/cve-2025-3717/
Scores
CVSS v4
2.1
EPSS
0.0026
EPSS Percentile
17.9%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-653
Status
published
Products (1)
Grafana Labs/Grafana Snowflake Datasource Plugin
1.5.0 - 1.14.1
Published
Nov 11, 2025
Tracked Since
Feb 18, 2026