A cross-site scripting (XSS) vulnerability exists in Grafana caused by client path traversal and open redirect. This allows attackers to redirect users to malicious websites that execute arbitrary JavaScript through custom frontend plugins. This vulnerability does not require editor permissions (as many other XSS usually does). If anonymous access is enabled, the XSS will work.This can be abused as a full read SSRF if the Grafana Image Renderer plugin is installed.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:7892 https://access.redhat.com/errata/RHSA-2025:7892
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7893 https://access.redhat.com/errata/RHSA-2025:7893
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:7894 https://access.redhat.com/errata/RHSA-2025:7894
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:8665 https://access.redhat.com/errata/RHSA-2025:8665
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:8684 https://access.redhat.com/errata/RHSA-2025:8684
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2025:8685 https://access.redhat.com/errata/RHSA-2025:8685
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:8681 https://access.redhat.com/errata/RHSA-2025:8681
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Via RHSA-2025:8683 https://access.redhat.com/errata/RHSA-2025:8683
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:8679 https://access.redhat.com/errata/RHSA-2025:8679
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:8680 https://access.redhat.com/errata/RHSA-2025:8680