Authorization Flaw in Grafana Alerting Integration Exposes Viewer Permissions
CVE-2025-3415

4.3MEDIUM

Key Information:

Vendor

Grafana

Status
Vendor
CVE Published:
17 July 2025

What is CVE-2025-3415?

The Grafana Alerting DingDing integration is subjected to an authorization flaw that allows users with Viewer permissions to gain inappropriate access. This vulnerability could potentially lead to data exposure if not properly mitigated. Grafana has addressed this issue in several versions, emphasizing the importance of upgrading to the latest security patches to maintain the integrity of the monitoring platform.

Affected Version(s)

Grafana 10.4.x < 10.4.19+security-01

Grafana 11.2.x < 11.2.10+security-01

Grafana 11.3.x < 11.3.7+security-01

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Saurabh Banawar
.
CVE-2025-3415 : Authorization Flaw in Grafana Alerting Integration Exposes Viewer Permissions