PT-2025-46532 · Grafana · Grafana Databricks Datasource Plugin
Published
2025-11-11
·
Updated
2025-11-11
·
CVE-2025-41116
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Grafana Databricks Datasource Plugin versions 1.12.1 through 1.12.0
Description
The Grafana Databricks Datasource Plugin has an issue where, with Oauth passthrough enabled, multiple users sharing a single Grafana instance and datasource may experience incorrect user identification. This can lead to unauthorized information disclosure, as data intended for one user may be accessible to others.
Recommendations
Update to a version after 1.12.0.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grafana Databricks Datasource Plugin