Deferred
Published: 18 Jul 2025, 07:48
Last modified:18 Jul 2025, 13:46

Vulnerability Summary

Overall Risk (default)
low
17/100
CVSS Score
4.2 MEDIUM
v3.1 (cve.org)
EPSS Score
1.02% LOW
1% probability +0.28%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Jul 2025, 07:48
Published
Vulnerability first disclosed
18 Jul 2025, 13:46
Last Modified
Vulnerability information updated

Description

An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL

CVSS Metrics

  • v3.1MEDIUMScore: 4.2CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

EPSS Trends

Current EPSS score: 1.02% Percentile: 78%

Techniques & Countermeasures

  • CWE-601URL Redirection to Untrusted Site ('Open Redirect')

    The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Affected Systems

  • grafanagrafana

    ≥ 12.0.x, < 12.0.2+security-01 | ≥ 11.6.x, < 11.6.3+security-01 | ≥ 11.5.x, < 11.5.6+security-01 | ≥ 11.4.x, < 11.4.6+security-01 | ≥ 11.3.x, < 11.3.8+security-01

References (2)