4.2
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Description
An open redirect vulnerability has been identified in Grafana OSS organization switching functionality.
Prerequisites for exploitation:
- Multiple organizations must exist in the Grafana instance
- Victim must be on a different organization than the one specified in the URL
Prerequisites for exploitation:
- Multiple organizations must exist in the Grafana instance
- Victim must be on a different organization than the one specified in the URL
Basic Information
ID
CVE-2025-6197
Source
GRAFANA
Published
Jul 18, 2025 at 07:48
Modified
Jul 18, 2025 at 13:46
Affected Product
Vendor
Grafana
Product
Grafana
Version
12.0.x
Affected Versions
Grafana Grafana 12.0.x
Grafana Grafana 11.6.x
Grafana Grafana 11.5.x
Grafana Grafana 11.4.x
Grafana Grafana 11.3.x
Grafana Grafana 11.6.x
Grafana Grafana 11.5.x
Grafana Grafana 11.4.x
Grafana Grafana 11.3.x