CVE-2025-4123
Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin in github.com/grafana/grafana
描述
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.
如何修補 CVE-2025-4123
要修補 CVE-2025-4123,請將受影響套件升級到下列已修補版本。
- —升級至 10.4.18 或更新版本
- —升級至 0.0.0-20250521183405-c7a690348df7 或更新版本
- —未列出修補版本
CVE-2025-4123 正在被利用嗎?
可能 — EPSS 為 97.8%,屬於高被利用機率區間,建議優先修補。
受影響套件(3)
- from 0, < 10.4.18, >= 11.0.0, < 11.6.1, >= 12.0.0, < 12.0.0
- from 0, < 0.0.0-20250521183405-c7a690348df7
- from 0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L |