CVE-2025-3415

Aliases:GHSA-46m5-8hpj-p5p5BIT-grafana-2025-3415GO-2025-3814CGA-32mw-76cv-r6jpCGA-35p9-x85q-hjvpCGA-38cf-g8h7-vj72CGA-44j3-pcvp-mhgjCGA-4j5v-pccx-3v56CGA-542g-crxj-mh29CGA-58c9-g59v-282rCGA-5rw8-cv7j-h7qqCGA-63gr-237v-vmxhCGA-8g8p-2mgf-74x7CGA-8jjv-364p-hcvhCGA-8r9j-7vrp-v49hCGA-8w9j-w2q9-jj7rCGA-9h5x-7jj4-87cpCGA-cq98-cgp9-7vhhCGA-g2xh-8m48-5m5cCGA-g4pw-gp8w-2cc4CGA-g8q7-q7m4-mjw2CGA-g9hg-cjvx-7f8jCGA-gxxx-j4m8-3wgfCGA-j6x9-2gjg-mf4rCGA-jrjm-hhf3-v277CGA-jxg4-x3m4-8hxcCGA-jxrq-9642-9xr5CGA-mgqr-3j7c-6fc9CGA-p47j-r5ch-23mjCGA-p64m-qvr2-qp8vCGA-p9g7-hfvv-v78cCGA-p9p4-m8gg-95w9CGA-phpg-cx94-6c2xCGA-q32x-qhg4-j9q8CGA-q9q5-r9v6-3gvmCGA-q9vx-wwx8-8vwpCGA-qq3w-4v3m-3wwvCGA-r4v2-hjm5-ggqpCGA-rh9f-c746-vw8jCGA-v996-c8qh-jg26CGA-x5gv-j64r-m9x3CGA-x6vf-j6xp-4fxhCGA-xrvm-c66f-38q8
Deferred
Published: 17 Jul 2025, 10:13
Last modified:17 Jul 2025, 14:05

Vulnerability Summary

Overall Risk (default)
low
17/100
CVSS Score
4.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.98% LOW
1% probability +0.65%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Jul 2025, 10:13
Published
Vulnerability first disclosed
17 Jul 2025, 14:05
Last Modified
Vulnerability information updated

Description

Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5+security-01, 11.6.2+security-01 and 12.0.1+security-01

CVSS Metrics

  • v3.1MEDIUMScore: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS Trends

Current EPSS score: 0.98% Percentile: 61%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • chainguardgrafana-fips-11.6

    < 0

  • chainguardgrafana-fips-12.0

    < 12.0.10-r6

  • chainguardgrafana-fips-12.1

    < 12.1.10.01-r3

  • chainguardgrafana-fips-12.2

    < 0

  • chainguardgrafana-fips-12.3

    < 0

  • chainguardgrafana-fips-12.4

    < 0

  • chainguardgrafana-fips-13.0

    < 0

  • chainguardgrafana-fips-13.1

    < 13.1.0-r0

  • github.com/grafanagrafana

    all | < 1.9.2-0.20250514160932-04111e9f2afd

  • grafanagrafana

    ≥ 10.4.x, < 10.4.19+security-01 | ≥ 11.2.x, < 11.2.10+security-01 | ≥ 11.3.x, < 11.3.7+security-01 | ≥ 11.4.x, < 11.4.5+security-01 | ≥ 11.5.x, < 11.5.5+security-01 | ≥ 11.6.x, < 11.6.2+security-01 | ≥ 12.0.x, < 12.0.1+security-01

References (12)