Cross-site scripting in Grafana - CVE-2025-4123
Published: May 22, 2025 / Updated: June 20, 2025
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via custom loaded frontend plugin. The vulnerability allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
grafana (Red Hat package)
grafana
grafana-selinux
How to mitigate CVE-2025-4123
grafana (Red Hat package) - addressed in versions 6.3.6-7.el8_2, 7.5.11-6.el8_6, 7.5.15-7.el8_8, 9.0.9-8.el9_2, 9.2.10-23.el8_10, 9.2.10-23.el9_4, 10.2.6-13.el9_6, 10.2.6-17.el10_0
grafana - update to 9.2.10-23.0.1
grafana-selinux - update to 9.2.10-23.0.1
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Cross-site scripting in Grafana
- Red Hat Enterprise Linux 10 update for grafana
- Red Hat Enterprise Linux 9 update for grafana
- Red Hat Enterprise Linux 8 update for grafana
- Anolis OS update for grafana
- Red Hat Enterprise Linux 9 update for grafana
- Red Hat Enterprise Linux 8 update for grafana
- Red Hat Enterprise Linux 9 update for grafana
- Red Hat Enterprise Linux 8 update for grafana
- Red Hat Enterprise Linux 8 update for grafana