S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jun 18, 2025

CVE-2025-3415 Scanner

CVE-2025-3415 Scanner - Information Disclosure vulnerability in Grafana

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-3415
4.3
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.

Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5+security-01, 11.6.2+security-01 and 12.0.1+security-01

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Grafanaby Grafana
AFFECTED< 10.4.19+security-01SAFE ✓≥ 10.4.19+security-01
Updated Aug 19, 2026View on NVD →
Detail

Grafana is a leading open-source platform for monitoring and observability, used by organizations worldwide to visualize metrics and data. It integrates with various data sources, providing powerful alerting and notification capabilities. Companies leverage Grafana to increase their infrastructure visibility, enabling quick and informed responses to system changes. It supports plugins and integrations with popular platforms such as DingDing for alert management. However, misconfigurations, especially in integration settings, can unintentionally expose sensitive data. This makes regular security checks crucial to maintain the integrity of the Grafana deployments.

The Information Disclosure vulnerability identified in Grafana under CVE-2025-3415 occurs due to an inappropriate exposure of DingDing integration API keys. Such exposures can result from software misconfiguration or legacy setting errors, making sensitive alert integration URLs accessible. Primarily impacting versions below or equal to 12.0.1, this vulnerability allows unauthorized users to view sensitive information. The issue underscores the necessity for diligent security configurations of integrated systems. Regular updates and security patches are essential to protect against such disclosures.

Technically, the vulnerability manifests in the /api/alertmanager/grafana/config/api/v1/alerts endpoint, where sensitive URLs could be inadvertently visible to unauthorized viewers. The exposure covers DingDing integration contexts and leverages HTTP responses containing JSON formatted data. When accessed, it returns a status code of 200, indicating a successful disclosure of potentially sensitive information. The vulnerable endpoint is typically leveraged in environments that use DingDing for alerts, increasing the risk in collaborative settings. Identifying the exposure often involves scrutinizing the content for DingTalk related contexts.

Exploiting this vulnerability could allow unauthorized parties to intercept or misuse the DingDing alert integration for malicious activities. Adversaries could manipulate alerting systems or gather intelligence about an organization's internal alert architecture. This might lead to misinformation or denial of service scenarios as attackers could forge or dismiss critical alerts. Moreover, exploitation could further result in the unauthorized triggering of alerts, leading to potential operational disruptions. The integrity of sensitive integrations and communications is at stake if this vulnerability is not promptly addressed.

REFERENCES

Solution Advice
  • Immediately update Grafana to a version greater than 12.0.1 to mitigate the issue.
  • Review and potentially reconfigure all alert integrations to ensure they adhere to security best practices.
  • Regularly audit and monitor alert configurations for unintended exposures.
  • Implement strict access controls around sensitive endpoints within your Grafana deployment.
  • Educate team members about the risks associated with integration misconfigurations and the importance of regular security reviews.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-3415 Scanner - Information Disclosure vulnerability in Grafana S4E