Fixed in versions 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5+security-01, 11.6.2+security-01 and 12.0.1+security-01
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21759 | Grafana's insecure DingDing Alert integration exposes sensitive information |
Github GHSA |
GHSA-46m5-8hpj-p5p5 | Grafana's insecure DingDing Alert integration exposes sensitive information |
Thu, 17 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Jul 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw exists in Grafana Alerting, where the DingDing contact-point integration URL can be revealed in plain text to users with viewer-level permissions due to misconfigured access control. This disclosure permits unauthorized users to view sensitive webhook URLs, including API tokens or keys, without needing elevated privileges. | Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5+security-01, 11.6.2+security-01 and 12.0.1+security-01 |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 25 Jun 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw exists in Grafana Alerting, where the DingDing contact-point integration URL can be revealed in plain text to users with viewer-level permissions due to misconfigured access control. This disclosure permits unauthorized users to view sensitive webhook URLs, including API tokens or keys, without needing elevated privileges. | |
| Title | grafana: Exposure of DingDing alerting integration URL to Viewer level users | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2025-07-17T14:05:19.284Z
Reserved: 2025-04-07T14:28:18.797Z
Link: CVE-2025-3415
Updated: 2025-07-17T14:05:09.376Z
Status : Deferred
Published: 2025-07-17T11:15:22.240
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-3415
OpenCVE Enrichment
Updated: 2025-07-21T15:17:18Z
EUVD
Github GHSA