| Type | URI |
|---|---|
| security@grafana.com | https://grafana.com/security/security-advisories/cve-2025-4123/ |
| security@grafana.com | https://grafana.com/blog/2025/05/23/grafana-security-release-medium-and-high-severity-security-fixes-for-cve-2025-4123-and-cve-2025-3580/ |
| CPE URI | Source package | Min version | Max version |
|---|---|---|---|
|
grafana | >= 10.4.18+security-01 | < 10.4.19 |
|
grafana | >= 11.2.9+security-01 | < 11.2.10 |
|
grafana | >= 11.3.6+security-01 | < 11.3.7 |
|
grafana | >= 11.4.4+security-01 | < 11.4.5 |
|
grafana | >= 11.5.4+security-01 | < 11.5.5 |
|
grafana | >= 11.6.1+security-01 | < 11.6.2 |
|
grafana | >= 12.0.0+security-01 | < 12.0.1 |
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* |
grafana | >= None | < 10.4.18 |
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* |
grafana | >= 11.2.0 | < 11.2.9 |
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* |
grafana | >= 11.3.0 | < 11.3.6 |
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* |
grafana | >= 11.4.0 | < 11.4.4 |
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* |
grafana | >= 11.5.0 | < 11.5.4 |
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* |
grafana | >= 11.6.0 | < 11.6.1 |
cpe:2.3:a:grafana:grafana:11.2.9:-:*:*:*:*:*:* |
grafana | == None | == 11.2.9 |
cpe:2.3:a:grafana:grafana:11.3.6:-:*:*:*:*:*:* |
grafana | == None | == 11.3.6 |
cpe:2.3:a:grafana:grafana:11.4.4:-:*:*:*:*:*:* |
grafana | == None | == 11.4.4 |
cpe:2.3:a:grafana:grafana:11.5.4:-:*:*:*:*:*:* |
grafana | == None | == 11.5.4 |
cpe:2.3:a:grafana:grafana:11.6.1:-:*:*:*:*:*:* |
grafana | == None | == 11.6.1 |
cpe:2.3:a:grafana:grafana:12.0.0:-:*:*:*:*:*:* |
grafana | == None | == 12.0.0 |
| Source package | Branch | Version | Maintainer | Status |
|---|---|---|---|---|
| grafana | edge-community | 12.0.0-r0 | Konstantin Kulikov <k.kulikov2@gmail.com> | possibly vulnerable |
| grafana | edge-community | 11.6.0-r2 | Konstantin Kulikov <k.kulikov2@gmail.com> | possibly vulnerable |
| grafana | edge-community | 11.6.0-r1 | Konstantin Kulikov <k.kulikov2@gmail.com> | possibly vulnerable |
| grafana | edge-community | 11.6.0-r0 | Konstantin Kulikov <k.kulikov2@gmail.com> | possibly vulnerable |
| grafana | edge-community | 11.5.2-r1 | Konstantin Kulikov <k.kulikov2@gmail.com> | possibly vulnerable |
| grafana | edge-community | 11.5.2-r0 | Konstantin Kulikov <k.kulikov2@gmail.com> | possibly vulnerable |
| grafana | edge-community | 11.5.1-r1 | Konstantin Kulikov <k.kulikov2@gmail.com> | possibly vulnerable |
| grafana | edge-community | 11.5.1-r0 | Konstantin Kulikov <k.kulikov2@gmail.com> | possibly vulnerable |
| grafana | edge-community | 11.5.0-r0 | Konstantin Kulikov <k.kulikov2@gmail.com> | possibly vulnerable |
| grafana | edge-community | 11.4.0-r1 | Konstantin Kulikov <k.kulikov2@gmail.com> | possibly vulnerable |
| grafana | edge-community | 11.4.0-r0 | Konstantin Kulikov <k.kulikov2@gmail.com> | possibly vulnerable |
| grafana | edge-community | 11.3.2-r0 | Konstantin Kulikov <k.kulikov2@gmail.com> | possibly vulnerable |
| grafana | edge-community | 11.3.1-r0 | Konstantin Kulikov <k.kulikov2@gmail.com> | possibly vulnerable |
| grafana | 3.22-community | 12.0.0-r3 | Konstantin Kulikov <k.kulikov2@gmail.com> | possibly vulnerable |
| grafana | 3.22-community | 12.0.0-r2 | Konstantin Kulikov <k.kulikov2@gmail.com> | possibly vulnerable |
| grafana | 3.22-community | 12.0.0-r1 | Konstantin Kulikov <k.kulikov2@gmail.com> | possibly vulnerable |
| grafana | 3.22-community | 11.3.1-r5 | Konstantin Kulikov <k.kulikov2@gmail.com> | possibly vulnerable |