CVE-2025-3454 log

Source
Severity Medium
Remote Yes
Type Access restriction bypass
Description
A vulnerability was found in Grafana's data source proxy API, which allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alert manager and Prometheus data sources. The issue primarily affects data sources that implement route-specific permissions, including Alert manager and certain Prometheus-based data sources.
Group Package Affected Fixed Severity Status Ticket
AVG-2884 grafana 11.6.1-1 Medium Vulnerable
References
https://grafana.com/blog/2025/04/22/grafana-security-release-medium-and-high-severity-fixes-for-cve-2025-3260-cve-2025-2703-cve-2025-3454/