CVE-2025-3415
Grafana vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2025-3415) was discovered in Grafana Alerting's DingDing contact-point integration. The vulnerability allows the integration URL to be exposed to users with viewer-level permissions. This security issue was disclosed on July 17, 2025, and affects multiple versions of Grafana (Grafana Labs, NVD).

Technical details

The vulnerability is classified as an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200). It has been assigned a CVSS v3.1 base score of 4.3 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N, indicating network accessibility, low attack complexity, low privileges required, no user interaction needed, and low confidentiality impact (NVD).

Impact

The vulnerability could result in the exposure of sensitive DingDing integration URLs to users with viewer permissions, potentially compromising the confidentiality of alert notification configurations (Grafana Labs).

Mitigation and workarounds

The vulnerability has been fixed in multiple Grafana versions including 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5+security-01, 11.6.2+security-01, and 12.0.1+security-01. Users are advised to upgrade to these patched versions (Grafana Labs).

Additional resources


SourceThis report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-15284HIGH8.7
  • JavaScriptJavaScript
  • renovate
NoYesDec 29, 2025
CVE-2026-22610HIGH8.5
  • JavaScriptJavaScript
  • firefox
NoYesJan 10, 2026
CVE-2026-22029HIGH8
  • JavaScriptJavaScript
  • grafana
NoYesJan 10, 2026
CVE-2025-68429HIGH7.3
  • JavaScriptJavaScript
  • grafana
NoYesDec 17, 2025
CVE-2025-14505MEDIUM5.6
  • JavaScriptJavaScript
  • grafana-postgres
NoNoJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management