A flaw exists in Grafana Alerting, where the DingDing contact-point integration URL can be revealed in plain text to users with viewer-level permissions due to misconfigured access control. This disclosure permits unauthorized users to view sensitive webhook URLs, including API tokens or keys, without needing elevated privileges.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Jun 2025 00:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw exists in Grafana Alerting, where the DingDing contact-point integration URL can be revealed in plain text to users with viewer-level permissions due to misconfigured access control. This disclosure permits unauthorized users to view sensitive webhook URLs, including API tokens or keys, without needing elevated privileges. | |
Title | grafana: Exposure of DingDing alerting integration URL to Viewer level users | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|

No data.

No data.

No data.
