Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-6197

Опубликовано: 22 июл. 2025
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation:

  • Multiple organizations must exist in the Grafana instance
  • Victim must be on a different organization than the one specified in the URL

    A flaw was found in Grafana, where the organization switching functionality caused an open redirect vulnerability. To make this exploitable, the Grafana instance must have more than one organization, and the user being redirected must be a member of both. Furthermore, the attacker needs to know the ID of the organization that the user is currently viewing.

Меры по смягчению последствий

Currently, no mitigation is available for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10grafanaFix deferred
Red Hat Enterprise Linux 8grafanaFix deferred
Red Hat Enterprise Linux 9grafanaFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-601

EPSS

Процентиль: 68%
0.00571
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
ubuntu
18 дней назад

An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL

CVSS3: 4.2
nvd
18 дней назад

An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL

CVSS3: 4.2
debian
18 дней назад

An open redirect vulnerability has been identified in Grafana OSS orga ...

CVSS3: 4.2
github
18 дней назад

An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL

CVSS3: 7.6
redos
6 дней назад

Множественные уязвимости grafana

EPSS

Процентиль: 68%
0.00571
Низкий

4.3 Medium

CVSS3