VDB
Sign up
MEDIUM5.0

GHSA-9j65-rv5x-4vrf

Grafana's datasource proxy API allows authorization checks to be bypassed

Quick fix

GHSA-9j65-rv5x-4vrf — github.com/grafana/grafana: upgrade to the fixed version with the command below.

go get github.com/grafana/grafana@v0.0.0-20250424191517-1f707d16ed5d

Details

This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path.

Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources.

The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/grafana/grafana
Introduced in: 0.0.0-20210414170620-dadccdda06e6Fixed in: 0.0.0-20250424191517-1f707d16ed5d
Fixgo get github.com/grafana/grafana@v0.0.0-20250424191517-1f707d16ed5d

References