CVE-2025-3454
Grafana's datasource proxy API allows authorization checks to be bypassed in github.com/grafana/grafana
5.0
MEDIUM
CVSS 3.1
EPSS 0.41%
描述
This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.
如何修補 CVE-2025-3454
要修補 CVE-2025-3454,請將受影響套件升級到下列已修補版本。
- —升級至 10.4.17 或更新版本
- —升級至 0.0.0-20250424191517-1f707d16ed5d 或更新版本
- —未列出修補版本
CVE-2025-3454 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- >= 10.4.0, < 10.4.17, >= 11.2.0, < 11.5.3, >= 11.6.0, < 11.6.0
- >= 0.0.0-20210414170620-dadccdda06e6, < 0.0.0-20250424191517-1f707d16ed5d
- >= 0.0.0-20210414170620-dadccdda06e6
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.0 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |