CVE-2025-3415Medium· 4.3▾ TwilightPoC availableGrafana's insecure DingDing Alert integration exposes sensitive information
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 23.7 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.0%
1.0% → 1.0%
Nuclei ×1 (last check)
Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5+security-01, 11.6.2+security-01 and 12.0.1+security-01.
github.com/grafana/grafana < 1.9.2-0.20250514160932-04111e9f2afdUpgrade to a patched release:
github.com/grafana/grafana 1.9.2-0.20250514160932-04111e9f2afdConnected by shared product, vendor, weakness, or advisory.
CVE-2023-3128Critical· 9.4Grafana vulnerable to Authentication Bypass by Spoofing
CVE-2021-43798High· 7.5Grafana path traversal
CVE-2021-39226High· 7.3Authentication bypass for viewing and deletions of snapshots
CVE-2023-22462Medium· 6.4Grafana vulnerable to Stored Cross-site Scripting in Text plugin
CVE-2020-13430Medium· 6.1Grafana XSS via the OpenTSDB datasource
CVE-2024-10452Low· 2.2Grafana org admin can delete pending invites in different org