CVE-2025-3454
Severity CVSS v4.0:
Pending analysis
Type:
CWE-285
Improper Authorization
Publication date:
02/06/2025
Last modified:
02/06/2025
Description
This vulnerability in Grafana&#39;s datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path.<br />
<br />
Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources.<br />
<br />
The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.
Impact
Base Score 3.x
5.00
Severity 3.x
MEDIUM



