Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-3415

23
FAUCET Score

CVE-2025-3415 describes an information disclosure vulnerability in Grafana's Alerting DingDing integration, where sensitive API keys could be exposed to users with Viewer permissions. This medium-severity vulnerability (CVSS 4.3) has a low attack complexity and does not impact availability or integrity, but could lead to unauthorized access to DingDing. While there is no evidence of active exploitation, a Nuclei template exists for detecting the exposure. Community discussion and media coverage for this CVE are currently minimal.

Impacted Technologies

VendorProductVersion(s)CPE
GrafanaGrafana
>= 10.4.x, < 10.4.19+security-01, >= 11.2.x, < 11.2.10+security-01, >= 11.3.x, < 11.3.7+security-01, >= 11.4.x, < 11.4.5+security-01, >= 11.5.x, < 11.5.5+security-01, >= 11.6.x, < 11.6.2+security-01, >= 12.0.x, < 12.0.1+security-01CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.89%
Probability of exploitation in next 30 days
EPSS Percentile
55.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
Nuclei: CVE-2025-3415 · Jun 18, 2025
This CVE's current EPSS score of 0.0089 is in the 68th percentile among its peer group of 21,977 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 1.9.2-0.20250514160932-04111e9f2afd
nodejspatch availablevia llm_extracted
View patch
apollographqlvendor investigatingvia llm_extracted
View patch
chainsafevendor investigatingvia llm_extracted
View patch
jenkinsvendor investigatingvia llm_extracted
View patch
kenticovendor investigatingvia llm_extracted
View patch
zimbravendor investigatingvia llm_extracted
View patch

Vendor Advisories (8)

goGHSA-46m5-8hpj-p5p5medium

Grafana's insecure DingDing Alert integration exposes sensitive information

Jul 17, 2025
zimbrallm-zimbra-0277a8c34371e6b0MEDIUM

Information Disclosure in DingDing Integration in Grafana

Jul 17, 2025
kenticollm-kentico-6c8f822ee6972effMEDIUM

Information Disclosure in DingDing Integration in Grafana

Jul 17, 2025
chainsafellm-chainsafe-f99afec97aca622aMEDIUM

Information Disclosure in DingDing Integration in Grafana

Jul 17, 2025
apollographqlllm-apollographql-4eb6175a48089754MEDIUM

Information Disclosure in DingDing Integration in Grafana

Jul 17, 2025
jenkinsllm-jenkins-16ae261989342475MEDIUM

Information Disclosure in DingDing Integration in Grafana

Jul 17, 2025
nodejsllm-nodejs-99b0819e1a512d8bMEDIUM

Information Disclosure in DingDing Integration in Grafana

Jul 17, 2025
redhatCVE-2025-3415Moderate

grafana: Exposure of DingDing alerting integration URL to Viewer level users

Jun 24, 2025

References

grafana.com / security/security-advisories/cve-2025-3415