Database/Control plane, storage & DevOps
Grafana: Client path traversal + open redirect
CVSS 7.6CVE-2025-4123Control plane, storage & DevOpscurated
Impact
Client path traversal + open redirect -> load an attacker-hosted frontend plugin and run arbitrary JS
Who can reach it
Network (remote)
What to do
Control-plane: upgrade; disable anonymous access
References
Related entries
- Grafana: Unauthenticated directory traversal via /public/plugins/<id>/CVE-2021-43798 · GrafanaHigh
- Grafana: Stored XSS via Unified AlertingCVE-2022-31097 · GrafanaHigh
- Grafana: A user can block another user's login by registering their email address as a usernameCVE-2022-39229 · GrafanaMedium
- Grafana: SQL Expressions passes user input to duckdb unsanitizedCVE-2024-9264 · GrafanaCritical
- Grafana: Unauthenticated access to snapshots via /api/snapshots/:keyCVE-2021-39226 · GrafanaCritical
- Grafana: Azure AD accounts validated on the mutable, non-unique email claimCVE-2023-3128 · GrafanaCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.