References https://nvd.nist.gov/vuln/detail/CVE-2025-3415 https://grafana.com/blog/grafana-security-update-medium-severity-security-release-for-cve-2025-3415/ https://ddpoc.com/DVB-2025-9483.html https://stack.chaitin.com/poc/detail/5043 https://stack.chaitin.com/vuldb/detail/419b7b2c-0f49-4f90-91f6-96ba9dd0d5b1 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-3415.yaml https://www.miggo.io/vulnerability-database/cve/CVE-2025-3415 https://knowledge.broadcom.com/external/article/420461/cve20253415-grafana-alerting-dingding-i.html https://grafana.com/security/security-advisories/cve-2025-3415 https://securityonline.info/grafana-alert-medium-severity-flaw-cve-2025-3415-exposes-dingding-api-keys/
Related VulnerabilitiesPoCgrafana-loki-api-exposure: Grafana Loki - Unauthenticated API AccessGrafana /api/ds/query DuckDB SQL 注入漏洞(CVE-2024-9264)Grafana Dashboard 权限管理不当漏洞PoCgrafana-unauth-access: Grafana Unauthenticated AccessPoCgrafana-metrics-exposure: Grafana Metrics Endpoint - Information DisclosureGrafana Grafana 权限管理不当漏洞Grafana Image Renderer 插件 需授权 文件上传限制不当漏洞 可导致远程代码执行Grafana存在重定向漏洞(CVE-2025-4123)Grafana /avatar 服务器端请求伪造漏洞(CVE-2020-13379)PoCCVE-2019-15043: Grafana - Improper Access Control