4.2
CVE-2025-6197
- EPSS 0.83%
- Published 18.07.2025 07:48:22
- Last modified 22.07.2025 13:06:27
- Source security@grafana.com
- Teams watchlist Login
- Open Login
An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorGrafana
≫
Product
Grafana
Default Statusunaffected
Version <
12.0.2+security-01
Version
12.0.x
Status
affected
Version <
11.6.3+security-01
Version
11.6.x
Status
affected
Version <
11.5.6+security-01
Version
11.5.x
Status
affected
Version <
11.4.6+security-01
Version
11.4.x
Status
affected
Version <
11.3.8+security-01
Version
11.3.x
Status
affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.83% | 0.738 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
security@grafana.com | 4.2 | 1.6 | 2.5 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
|
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.