From 49fd60e6a263da25cbfc6b32f060cd2050bc21bd Mon Sep 17 00:00:00 2001 From: Boris Korzun Date: Wed, 18 Jun 2025 19:45:19 +0200 Subject: [PATCH] security/vuxml: Add grafana vulnerability While here, correct versions for a previous grafana entry. PR: 287634 Reported by: Boris Korzun --- security/vuxml/vuln/2025.xml | 118 ++++++++++++++++++++++++++++++++++- 1 file changed, 116 insertions(+), 2 deletions(-) diff --git a/security/vuxml/vuln/2025.xml b/security/vuxml/vuln/2025.xml index c59348b27dc0..5ebc716f5bb8 100644 --- a/security/vuxml/vuln/2025.xml +++ b/security/vuxml/vuln/2025.xml @@ -1,3 +1,103 @@ + + Grafana -- DingDing contact points exposed in Grafana Alerting + + + grafana + 10.4.19+security-01 + 11.0.011.2.10+security-01 + 11.3.011.3.7+security-01 + 11.4.011.4.5+security-01 + 11.5.011.5.5+security-01 + 11.6.011.6.2+security-01 + 12.0.012.0.1+security-01 + + + grafana8 + 8.0.0 + + + grafana9 + 9.0.0 + + + + +

Grafana Labs reports:

+
+

An incident occurred where the DingDing alerting integration URL + was inadvertently exposed to viewers due to a setting oversight, + which we learned about through a bug bounty report.

+

The CVSS 3.0 score for this vulnerability is 4.3 (Medium).

+
+ +
+ + CVE-2025-3415 + https://grafana.com/blog/2025/06/13/grafana-security-update-medium-severity-security-release-for-cve-2025-3415/ + + + 2025-04-05 + 2025-06-18 + +
+ + + Grafana -- User deletion issue + + + grafana + 5.4.010.4.18+security-01 + 11.0.011.2.9+security-01 + 11.3.011.3.6+security-01 + 11.4.011.4.4+security-01 + 11.5.011.5.4+security-01 + 11.6.011.6.1+security-01 + 12.0.012.0.0+security-01 + + + grafana8 + 8.0.0 + + + grafana9 + 9.0.0 + + + + +

Grafana Labs reports:

+
+

On April 15, we discovered a vulnerability that stems from the user + deletion logic associated with organization administrators. + An organization admin could remove any user from the specific + organization they manage. Additionally, they have the power to delete + users entirely from the system if they have no other org membership. + This leads to two situations:

+
    +
  1. They can delete a server admin if the organization + the Organization Admin manages is the server admin’s final + organizational membership.
  2. +
  3. They can delete any user (regardless of whether they are a server + admin or not) if that user currently belongs to no organizations.
  4. +
+

These two situations allow an organization manager to disrupt + instance-wide activity by continually deleting server administrators + if there is only one organization or if the server administrators are + not part of any organization.

+

The CVSS score for this vulnerability is 5.5 Medium.

+
+ +
+ + CVE-2025-3580 + https://grafana.com/blog/2025/05/23/grafana-security-release-medium-and-high-severity-security-fixes-for-cve-2025-4123-and-cve-2025-3580/ + + + 2025-04-15 + 2025-05-23 + +
+ Firefox -- Multiple vulnerabilities @@ -1225,7 +1325,21 @@ grafana - 12.0.1 + 8.0.010.4.18+security-01 + 11.0.011.2.9+security-01 + 11.3.011.3.6+security-01 + 11.4.011.4.4+security-01 + 11.5.011.5.4+security-01 + 11.6.011.6.1+security-01 + 12.0.012.0.0+security-01 + + + grafana8 + 8.0.0 + + + grafana9 + 9.0.0 @@ -1251,7 +1365,7 @@ https://nvd.nist.gov/vuln/detail/CVE-2025-4123 - 2025-05-22 + 2025-04-26 2025-05-27