CVE-2025-3454

Name
CVE-2025-3454
Description
This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security@grafana.com https://grafana.com/security/security-advisories/cve-2025-3454/

Match rules

CPE URI Source package Min version Max version
grafana >= 11.6.0 < 11.6.0+security-01
grafana >= 11.5.0 < 11.5.3+security-01
grafana >= 11.4.0 < 11.4.3+security-01
grafana >= 11.3.0 < 11.3.5+security-01
grafana >= 11.2.0 < 11.2.8+security-01
grafana >= 10.4.0 < 10.4.17+security-01
grafana-enterprise >= 11.6.0 < 11.6.0+security-01
grafana-enterprise >= 11.5.0 < 11.5.3+security-01
grafana-enterprise >= 11.4.0 < 11.4.3+security-01
grafana-enterprise >= 11.3.0 < 11.3.5+security-01
grafana-enterprise >= 11.2.0 < 11.2.8+security-01
grafana-enterprise >= 10.4.0 < 10.4.17+security-01

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
grafana edge-community 11.6.1-r0 None fixed
grafana edge-community 11.6.0-r2 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.6.0-r1 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.6.0-r0 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.5.2-r1 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.5.2-r0 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.5.1-r1 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.5.1-r0 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.5.0-r0 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.4.0-r1 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.4.0-r0 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.3.2-r0 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.3.1-r0 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana 3.22-community 11.6.1-r0 None fixed
grafana 3.22-community 11.3.1-r5 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable