CVE-2025-4123
Summary
| CVE | CVE-2025-4123 |
|---|---|
| State | PUBLISHED |
| Assigner | GRAFANA |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-05-22 08:15:52 UTC |
| Updated | 2026-04-29 20:16:28 UTC |
| Description | A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive. |
Risk And Classification
Primary CVSS: v3.1 6.1 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Problem Types: CWE-79 | CWE-601 | CWE-79 CWE-79 | CWE-601 CWE-601
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 6.1 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| 3.1 | [email protected] | Secondary | 7.6 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L |
| 3.1 | CNA | CVSS | 7.6 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Grafana | Grafana | affected 10.4.18+security-01 10.4.19 semver | Not specified |
| CNA | Grafana | Grafana | affected 11.2.9+security-01 11.2.10 semver | Not specified |
| CNA | Grafana | Grafana | affected 11.3.6+security-01 11.3.7 semver | Not specified |
| CNA | Grafana | Grafana | affected 11.4.4+security-01 11.4.5 semver | Not specified |
| CNA | Grafana | Grafana | affected 11.5.4+security-01 11.5.5 semver | Not specified |
| CNA | Grafana | Grafana | affected 11.6.1+security-01 11.6.2 semver | Not specified |
| CNA | Grafana | Grafana | affected 12.0.0+security-01 12.0.1 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.exploit-db.com/exploits/52491 | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| grafana.com/blog/2025/05/23/grafana-security-release-medium-and-high-seve... | [email protected] | grafana.com | Vendor Advisory |
| grafana.com/security/security-advisories/cve-2025-4123 | [email protected] | grafana.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Alvaro Balada (en)
There are currently no legacy QID mappings associated with this CVE.