This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path.
Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources.
The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.
Metrics
Affected Vendors & Products
References
History
Mon, 02 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 02 Jun 2025 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in Grafana's data source proxy API, which allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alert manager and Prometheus data sources. The issue primarily affects data sources that implement route-specific permissions, including Alert manager and certain Prometheus-based data sources. | This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources. |
Weaknesses | CWE-285 | |
References |
| |
Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 23 Apr 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in Grafana's data source proxy API, which allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alert manager and Prometheus data sources. The issue primarily affects data sources that implement route-specific permissions, including Alert manager and certain Prometheus-based data sources. | |
Title | grafana: Unauthorized Data Source Access in Grafana via URL Path Manipulation | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|

Status: PUBLISHED
Assigner: GRAFANA
Published: 2025-06-02T10:34:09.254Z
Updated: 2025-06-02T12:04:24.348Z
Reserved: 2025-04-08T20:40:44.631Z
Link: CVE-2025-3454

Updated: 2025-06-02T12:04:17.633Z

Status : Awaiting Analysis
Published: 2025-06-02T11:15:22.167
Modified: 2025-06-02T17:32:17.397
Link: CVE-2025-3454
