CVE-2025-3717

LOW

Grafana Snowflake Datasource Plugin <1.14.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

When using the Grafana Snowflake Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, it  could result in  the wrong user identifier being used, and information for which the viewer is not authorized being returned.  This issue affects Grafana Snowflake Datasource Plugin: from 1.5.0 before 1.14.1.

References (1)

Core 1

Scores

CVSS v4 2.1
EPSS 0.0026
EPSS Percentile 17.9%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-653
Status published
Products (1)
Grafana Labs/Grafana Snowflake Datasource Plugin 1.5.0 - 1.14.1
Published Nov 11, 2025
Tracked Since Feb 18, 2026