An exposure vulnerability in Grafana Alerting’s DingDing integration reveals the full webhook URL including embedded API tokens or keys to users with Viewer-level access. The issue stems from insufficient access control, allowing unauthorized users to view sensitive integration details. This could enable attackers to send spoofed or malicious alerts via the DingDing channel without needing further authentication or interaction. Impacted versions :Grafana versions <=12.0.1