CVE-2025-3454

Severity CVSS v4.0:
Pending analysis
Type:
CWE-285 Improper Authorization
Publication date:
02/06/2025
Last modified:
02/06/2025

Description

This vulnerability in Grafana&amp;#39;s datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path.<br /> <br /> Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources.<br /> <br /> The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.

References to Advisories, Solutions, and Tools