CVE 2.1 LOW

Incorrect oauth passthrough in Grafana Snowflake Datasource_CVE-2025-41116

2.1 / 10
LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N

Description

When using the Grafana Databricks Datasource Plugin,
if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, itΒ  could result inΒ 

the wrong user identifier being used, and information for which the viewer is not authorized being returned.Β 

This issue affects Grafana Databricks Datasource Plugin: from 1.12.1 before 1.12.0

Basic Information

ID CVE-2025-41116
Source GRAFANA
Published Nov 11, 2025 at 20:18

Affected Product

Vendor Grafana Labs
Product Grafana Databricks Datasource Plugin
Version 1.6.0
Affected Versions Grafana Labs Grafana Databricks Datasource Plugin 1.6.0

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.