Grafana is an open-source platform for monitoring and observability. The Infinity datasource plugin, maintained by Grafana Labs, allows visualizing data from JSON, CSV, XML, GraphQL, and HTML endpoints. If the plugin was configured to allow only certain URLs, an attacker could bypass this restriction using a specially crafted URL. This vulnerability is fixed in version 3.4.1.
History

Tue, 05 Aug 2025 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Grafana
Grafana grafana
Grafana infinity Datasource
Vendors & Products Grafana
Grafana grafana
Grafana infinity Datasource

Mon, 04 Aug 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 04 Aug 2025 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 04 Aug 2025 08:45:00 +0000

Type Values Removed Values Added
Description Grafana is an open-source platform for monitoring and observability. The Infinity datasource plugin, maintained by Grafana Labs, allows visualizing data from JSON, CSV, XML, GraphQL, and HTML endpoints. If the plugin was configured to allow only certain URLs, an attacker could bypass this restriction using a specially crafted URL. This vulnerability is fixed in version 3.4.1.
Title SSRF in Infinity Datasource Plugin
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GRAFANA

Published: 2025-08-04T08:34:50.669Z

Updated: 2025-08-04T16:13:49.206Z

Reserved: 2025-07-30T08:39:45.330Z

Link: CVE-2025-8341

cve-icon Vulnrichment

Updated: 2025-08-04T16:12:09.371Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-04T09:15:26.103

Modified: 2025-08-04T15:06:15.833

Link: CVE-2025-8341

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-08-04T08:34:50Z

Links: CVE-2025-8341 - Bugzilla