Bug 2374538 (CVE-2025-3415) - CVE-2025-3415 grafana: Exposure of DingDing alerting integration URL to Viewer level users
Summary: CVE-2025-3415 grafana: Exposure of DingDing alerting integration URL to Viewe...
Keywords:
Status: NEW
Alias: CVE-2025-3415
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2374546 2374548
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-06-24 11:41 UTC by OSIDB Bzimport
Modified: 2025-06-24 12:37 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-06-24 11:41:51 UTC
An exposure vulnerability in Grafana Alerting’s DingDing integration reveals the full webhook URL including embedded API tokens or keys to users with Viewer-level access. The issue stems from insufficient access control, allowing unauthorized users to view sensitive integration details. This could enable attackers to send spoofed or malicious alerts via the DingDing channel without needing further authentication or interaction.

Impacted versions :Grafana versions <=12.0.1


Note You need to log in before you can comment on or make changes to this bug.