We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-6023



Description

An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fixed in versions 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01 and 11.3.8+security-01

Reserved 2025-06-12 | Published 2025-07-18 | Updated 2025-07-18 | Assigner GRAFANA


HIGH: 7.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L

Problem types

CWE-601

CWE-79

Product status

Default status
unaffected

12.0.x before 12.0.2+security-01
affected

11.6.x before 11.6.3+security-01
affected

11.5.x before 11.5.6+security-01
affected

11.4.x before 11.4.6+security-01
affected

11.3.x before 11.3.8+security-01
affected

Credits

Hoa X. Nguyen finder

References

grafana.com/security/security-advisories/cve-2025-6023/ (Security vulnerability management issue) vendor-advisory

grafana.com/...ty-fixes-for-cve-2025-6197-and-cve-2025-6023/ release-notes mitigation

cve.org (CVE-2025-6023)

nvd.nist.gov (CVE-2025-6023)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-6023

Support options

Helpdesk Chat, Email, Knowledgebase