CVE-2025-3415
Grafana vulnerability analysis and mitigation

Overview

CVE-2025-3415 is a medium-severity information disclosure vulnerability in Grafana's Alerting DingDing integration that exposes sensitive webhook URLs — including embedded API tokens or keys — to users with Viewer-level permissions. The vulnerability affects Grafana versions across multiple release branches: 10.4.x before 10.4.19+security-01, 11.2.x before 11.2.10+security-01, 11.3.x before 11.3.7+security-01, 11.4.x before 11.4.5+security-01, 11.5.x before 11.5.5+security-01, 11.6.x before 11.6.2+security-01, and 12.0.x before 12.0.1+security-01. It was first reported on June 24, 2025, published to the GitHub Advisory Database on July 17, 2025, and carries a CVSS v3.1 base score of 4.3 (Medium) (Red Hat Bugzilla, GitHub Advisory).

Technical details

The root cause is insufficient access control (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) in the Grafana Alerting DingDing integration configuration endpoint. The integration's webhook URL — which may contain embedded API tokens or secret keys — is not properly restricted, allowing any authenticated user with Viewer-level permissions to read it via a network request. Exploitation requires only a valid low-privileged account on the Grafana instance and no user interaction, making the attack straightforward for any internal or external user with Viewer access. A Nuclei detection template has been published for this vulnerability, enabling automated scanning (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation allows a Viewer-level user to retrieve the full DingDing webhook URL, including any embedded API tokens or secret keys configured for alerting. With this information, an attacker could send spoofed or malicious alerts to the DingDing channel without further authentication, potentially disrupting operations or conducting social engineering attacks against recipients. There is no direct integrity or availability impact on the Grafana instance itself, but the exposed credentials could be leveraged for unauthorized access to the DingDing messaging platform (Red Hat Bugzilla, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify Grafana instances running affected versions (10.4.x–12.0.x before the security-01 patch releases) using Shodan, Censys, or the Nuclei template http/cves/2025/CVE-2025-3415.yaml.
  2. Obtain Viewer credentials: Acquire or register a low-privileged Viewer account on the target Grafana instance (e.g., via self-registration if enabled, or using compromised credentials).
  3. Access DingDing integration endpoint: Authenticate to Grafana and send an HTTP GET request to the alerting notification channel configuration endpoint that exposes DingDing integration details.
  4. Extract webhook URL and API token: Parse the response to retrieve the full DingDing webhook URL, including any embedded API keys or tokens.
  5. Abuse extracted credentials: Use the extracted webhook URL to send unauthorized or spoofed alert messages to the DingDing channel, or use the API token for further unauthorized actions against the DingDing API (Red Hat Bugzilla, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP GET requests from Viewer-level accounts to Grafana alerting notification channel configuration endpoints (e.g., /api/alert-notifications or similar DingDing integration API paths).
  • Logs: Grafana access logs showing Viewer-role users querying alerting integration configuration endpoints, particularly outside normal usage patterns or from unusual source IPs.
  • DingDing: Unexpected or unauthorized messages appearing in DingDing channels configured as Grafana alerting targets, especially messages not corresponding to any real Grafana alert event.

Mitigation and workarounds

Grafana has released patched versions addressing this vulnerability: 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5+security-01, 11.6.2+security-01, and 12.0.1+security-01. Organizations should upgrade to the appropriate patched release immediately. As interim mitigations, administrators should review and restrict Viewer-level user access, audit existing DingDing webhook URLs and rotate any potentially exposed API tokens, and monitor Grafana access logs for anomalous queries to alerting configuration endpoints (GitHub Advisory, Grafana Advisory).

Community reactions

Grafana published a security blog post on June 13, 2025 announcing the medium-severity release for CVE-2025-3415, and the vulnerability received coverage from SecurityOnline.info highlighting the exposure of DingDing API keys. The issue was also noted in the Secret CISO newsletter and discussed briefly on Bluesky by infosec community members. Overall community reaction has been measured given the medium severity and limited exploitation potential (Grafana Blog, SecurityOnline).

Additional resources


SourceThis report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8609HIGH7.5
  • Grafana logoGrafana
  • grafana-fips-12.3
NoYesJul 10, 2026
CVE-2026-8595MEDIUM5.4
  • Grafana logoGrafana
  • grafana-fips-13.0
NoYesJul 10, 2026
CVE-2026-21723MEDIUM5.3
  • Grafana logoGrafana
  • grafana-opentsdb
NoNoJul 23, 2026
CVE-2026-66010MEDIUM5.1
  • Grafana logoGrafana
  • librados-devel
NoYesJul 24, 2026
CVE-2026-65903MEDIUM5.1
  • JavaScript logoJavaScript
  • librechat
NoYesJul 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management