VDB
GO-2025-3740
GO-2025-3740
PUBLISHED
CVSS 8.600000381469727 HIGH
Grafana vulnerable to authenticated users bypassing dashboard, folder permissions in github.com/grafana/grafana
Risk Scores
CVSS v4.0
8.600000381469727
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | grafana/grafana | 0.0.0-20250114093457-36d6fad421fb, 0.0.0-20250114093457 |
Timeline
- Jun 9, 2025 CVE Published
- Jun 9, 2025 CVE Updated
- May 1, 2026 Security Advisory
References
- https://github.com/advisories/GHSA-3px7-c4j3-576r advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-3260 advisory
- https://github.com/grafana/grafana/blob/be8d153dc33734caba4f617ff571d18253e68fa0/CHANGELOG.md#1161-2025-04-23 url
- https://grafana.com/blog/2025/04/22/grafana-security-release-medium-and-high-severity-fixes-for-cve-2025-3260-cve-2025-2703-cve-2025-3454 url