VDB
BDU%3A2025-06809
BDU%3A2025-06809
PUBLISHED
CVSS 9 CRITICAL
Уязвимость компонента Custom Frontend Plugin платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)
Risk Scores
CVSS 2.0
9
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., ООО «Ред Софт», Grafana Labs, ООО «РусБИТех-Астра» | Red Hat Enterprise Linux, РЕД ОС (запись в едином реестре российских программ №3751), Grafana, ПК "ALD Pro" |
Timeline
- Jun 16, 2025 CVE Published
- Nov 26, 2025 CVE Updated
References
- https://access.redhat.com/security/cve/cve-2025-4123 url
- https://grafana.com/grafana/plugins/instana-datasource/?tab=changelog url
- https://github.com/NightBloodz/CVE-2025-4123 url
- https://t.me/bizone_channel/1899 url
- https://grafana.com/security/security-advisories/cve-2025-4123/ url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://lk.astra.ru/ url
- https://wiki.astralinux.ru/x/ziLoD url