CVE-2025-6197
Advisory lineage Upstream: 0 Downstream: 7
Deferred
Published: 18 Jul 2025, 07:48
Last modified:18 Jul 2025, 13:46
Vulnerability Summary
Overall Risk (default)
low
17/100 CVSS Score
4.2 MEDIUM
v3.1 (cve.org)
EPSS Score
1.02% LOW
1% probability +0.28%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
18 Jul 2025, 07:48
Published
Vulnerability first disclosed
18 Jul 2025, 13:46
Last Modified
Vulnerability information updated
Description
An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL
CVSS Metrics
- v3.1•MEDIUM•Score: 4.2CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS Trends
Current EPSS score: 1.02%• Percentile: 78%
Techniques & Countermeasures
- CWE-601•URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Affected Systems
- grafana•grafana
≥ 12.0.x, < 12.0.2+security-01 | ≥ 11.6.x, < 11.6.3+security-01 | ≥ 11.5.x, < 11.5.6+security-01 | ≥ 11.4.x, < 11.4.6+security-01 | ≥ 11.3.x, < 11.3.8+security-01