CVE-2025-6023

Name
CVE-2025-6023
Description
An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fixed in versions 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01 and 11.3.8+security-01
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
release-notes https://grafana.com/blog/2025/07/17/grafana-security-release-medium-and-high-severity-fixes-for-cve-2025-6197-and-cve-2025-6023/
vendor-advisory https://grafana.com/security/security-advisories/cve-2025-6023/

Match rules

CPE URI Source package Min version Max version
grafana >= 12.0.x < 12.0.2+security-01
grafana >= 11.6.x < 11.6.3+security-01
grafana >= 11.5.x < 11.5.6+security-01
grafana >= 11.4.x < 11.4.6+security-01
grafana >= 11.3.x < 11.3.8+security-01

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
grafana edge-community 11.3.1-r0 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.3.2-r0 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.4.0-r0 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.4.0-r1 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.5.0-r0 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.5.1-r0 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.5.1-r1 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.5.2-r0 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.5.2-r1 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.6.0-r0 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.6.0-r1 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 11.6.0-r2 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 12.0.0-r0 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 12.0.1-r0 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 12.0.2-r0 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 12.0.2-r1 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana edge-community 12.0.2-r2 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana 3.22-community 11.3.1-r5 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana 3.22-community 12.0.0-r1 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana 3.22-community 12.0.0-r2 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable
grafana 3.22-community 12.0.0-r3 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable