
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-3415 is a medium-severity information disclosure vulnerability in Grafana's Alerting DingDing integration that exposes sensitive webhook URLs — including embedded API tokens or keys — to users with Viewer-level permissions. The vulnerability affects Grafana versions across multiple release branches: 10.4.x before 10.4.19+security-01, 11.2.x before 11.2.10+security-01, 11.3.x before 11.3.7+security-01, 11.4.x before 11.4.5+security-01, 11.5.x before 11.5.5+security-01, 11.6.x before 11.6.2+security-01, and 12.0.x before 12.0.1+security-01. It was first reported on June 24, 2025, published to the GitHub Advisory Database on July 17, 2025, and carries a CVSS v3.1 base score of 4.3 (Medium) (Red Hat Bugzilla, GitHub Advisory).
The root cause is insufficient access control (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) in the Grafana Alerting DingDing integration configuration endpoint. The integration's webhook URL — which may contain embedded API tokens or secret keys — is not properly restricted, allowing any authenticated user with Viewer-level permissions to read it via a network request. Exploitation requires only a valid low-privileged account on the Grafana instance and no user interaction, making the attack straightforward for any internal or external user with Viewer access. A Nuclei detection template has been published for this vulnerability, enabling automated scanning (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation allows a Viewer-level user to retrieve the full DingDing webhook URL, including any embedded API tokens or secret keys configured for alerting. With this information, an attacker could send spoofed or malicious alerts to the DingDing channel without further authentication, potentially disrupting operations or conducting social engineering attacks against recipients. There is no direct integrity or availability impact on the Grafana instance itself, but the exposed credentials could be leveraged for unauthorized access to the DingDing messaging platform (Red Hat Bugzilla, GitHub Advisory).
http/cves/2025/CVE-2025-3415.yaml./api/alert-notifications or similar DingDing integration API paths).Grafana has released patched versions addressing this vulnerability: 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5+security-01, 11.6.2+security-01, and 12.0.1+security-01. Organizations should upgrade to the appropriate patched release immediately. As interim mitigations, administrators should review and restrict Viewer-level user access, audit existing DingDing webhook URLs and rotate any potentially exposed API tokens, and monitor Grafana access logs for anomalous queries to alerting configuration endpoints (GitHub Advisory, Grafana Advisory).
Grafana published a security blog post on June 13, 2025 announcing the medium-severity release for CVE-2025-3415, and the vulnerability received coverage from SecurityOnline.info highlighting the exposure of DingDing API keys. The issue was also noted in the Secret CISO newsletter and discussed briefly on Bluesky by infosec community members. Overall community reaction has been measured given the medium severity and limited exploitation potential (Grafana Blog, SecurityOnline).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."