References https://nvd.nist.gov/vuln/detail/CVE-2025-4123 https://grafana.com/security/security-advisories/cve-2025-4123/ https://grafana.com/blog/2025/05/23/grafana-security-release-medium-and-high-severity-security-fixes-for-cve-2025-4123-and-cve-2025-3580/ https://grafana.com/blog/grafana-security-release-high-severity-security-fix-for-cve-2025-4123/ https://www.ionix.io/blog/grafana-cve-2025-4123-open-redirect-stored-xss-patch/ https://nightbloodz.github.io/grafana-CVE-2025-4123/ https://www.exploit-db.com/exploits/52491 https://www.sonicwall.com/blog/high-severity-open-redirect-vulnerability-in-grafana-leads-to-account-takeover-cve-2025-4123 https://github.com/ynsmroztas/CVE-2025-4123-Exploit-Tool-Grafana- https://access.redhat.com/security/cve/cve-2025-4123
Related VulnerabilitiesPoCgrafana-loki-api-exposure: Grafana Loki - Unauthenticated API AccessGrafana /api/ds/query DuckDB SQL 注入漏洞(CVE-2024-9264)Grafana Dashboard 权限管理不当漏洞PoCgrafana-unauth-access: Grafana Unauthenticated AccessPoCgrafana-metrics-exposure: Grafana Metrics Endpoint - Information DisclosureGrafana Grafana 权限管理不当漏洞Grafana Image Renderer 插件 需授权 文件上传限制不当漏洞 可导致远程代码执行Grafana /avatar 服务器端请求伪造漏洞(CVE-2020-13379)PoCCVE-2019-15043: Grafana - Improper Access ControlPoCCVE-2020-11110: Grafana <= 6.7.1 - Cross-Site Scripting