Open Redirect Vulnerability in Grafana OSS Affecting Multiple Organizations
CVE-2025-6197
4.2MEDIUM
What is CVE-2025-6197?
An open redirect vulnerability has been detected in Grafana OSS, specifically within the organization switching functionality. This security issue arises when users switch organizations, allowing malicious actors to potentially redirect victims to arbitrary URLs. For exploitation, the Grafana instance must have multiple organizations, and the victim must belong to a different organization than the one indicated in the provided URL. Organizations using Grafana are advised to review their settings and implement necessary patches to mitigate this vulnerability.
Affected Version(s)
Grafana 12.0.x < 12.0.2+security-01
Grafana 11.6.x < 11.6.3+security-01
Grafana 11.5.x < 11.5.6+security-01