Количество 8
Количество 8
GHSA-9j65-rv5x-4vrf
Grafana's datasource proxy API allows authorization checks to be bypassed
CVE-2025-3454
This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.
CVE-2025-3454
This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.
CVE-2025-3454
This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.
CVE-2025-3454
This vulnerability in Grafana's datasource proxy API allows authorizat ...
SUSE-SU-2025:01991-1
Security update for grafana
SUSE-SU-2025:01989-1
Security update for Multi-Linux Manager Client Tools
SUSE-SU-2025:01987-1
Security update for Multi-Linux Manager Client Tools
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-9j65-rv5x-4vrf Grafana's datasource proxy API allows authorization checks to be bypassed | CVSS3: 5 | 0% Низкий | 7 месяцев назад | |
CVE-2025-3454 This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources. | CVSS3: 5 | 0% Низкий | 7 месяцев назад | |
CVE-2025-3454 This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources. | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
CVE-2025-3454 This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources. | CVSS3: 5 | 0% Низкий | 7 месяцев назад | |
CVE-2025-3454 This vulnerability in Grafana's datasource proxy API allows authorizat ... | CVSS3: 5 | 0% Низкий | 7 месяцев назад | |
SUSE-SU-2025:01991-1 Security update for grafana | 6 месяцев назад | |||
SUSE-SU-2025:01989-1 Security update for Multi-Linux Manager Client Tools | 6 месяцев назад | |||
SUSE-SU-2025:01987-1 Security update for Multi-Linux Manager Client Tools | 6 месяцев назад |
Уязвимостей на страницу