PT-2025-17604 · Grafana+1 · Grafana+1

Published

2025-04-23

·

Updated

2025-09-19

·

CVE-2025-3454

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grafana version 10.4.0
Description The issue concerns improper authorization in the Data Source Proxy API.
Recommendations For Grafana version 10.4.0, update to a version that includes the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Weakness Enumeration

Related Identifiers

BIT-GRAFANA-2025-3454
CVE-2025-3454
GHSA-9J65-RV5X-4VRF
GO-2025-3742
OPENSUSE-SU-2025:15052-1
OPENSUSE-SU-2025:15225-1
SUSE-SU-2025:01985-1
SUSE-SU-2025:01987-1
SUSE-SU-2025:01989-1
SUSE-SU-2025:01991-1
SUSE-SU-2025_01987-1

Affected Products

Grafana
Suse