Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-12141

Опубликовано: 15 апр. 2026
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations.

A flaw was found in Grafana's alerting system. Users with editor permissions, specifically those able to write or test alert notifications, can modify contact points created by other users. By changing the endpoint URL to a controlled server and triggering the test functionality, an attacker can capture and extract sensitive secure settings, such as authentication credentials for third-party services. This vulnerability leads to unauthorized access and potential compromise of external integrations.

Отчет

This vulnerability has a Low impact on Red Hat products. The flaw in Grafana's alerting system allows an authenticated user with "Contact Point Writer" permissions (part of the Editor role) to disclose secure settings. Exploitation requires the attacker to modify an existing contact point and test it against a controlled external server.

Меры по смягчению последствий

To mitigate this issue, administrators should review and restrict user permissions within Grafana. Ensure that only trusted users are granted the "Contact Point Writer" role or any role that includes "alert.notifications:write" or "alert.notifications.receivers:test" permissions. Limiting the number of users with such elevated privileges reduces the attack surface. If the Grafana service is reconfigured, a restart may be required for changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Global HubgrafanaFix deferred
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Fix deferred
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Fix deferred
Red Hat Enterprise Linux 10grafanaFix deferred
Red Hat Enterprise Linux 8grafanaFix deferred
Red Hat Enterprise Linux 9grafanaFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2458704Grafana: Grafana: Information disclosure of secure settings via contact point modification

EPSS

Процентиль: 17%
0.00255
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 месяца назад

In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations.

CVSS3: 6.5
nvd
4 месяца назад

In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations.

CVSS3: 6.5
debian
4 месяца назад

In Grafana's alerting system, users with edit permissions for a contac ...

CVSS3: 6.5
github
4 месяца назад

In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations.

CVSS3: 4.3
fstec
4 месяца назад

Уязвимость системы оповещений платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 17%
0.00255
Низкий

5 Medium

CVSS3