Improper Preservation of Permissions Affecting github.com/grafana/grafana/pkg/api/pluginproxy package, versions >=11.6.0 <11.6.0+security-01


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMGRAFANAGRAFANAPKGAPIPLUGINPROXY-9833943
  • published28 Apr 2025
  • disclosed25 Apr 2025
  • creditUnknown

Introduced: 25 Apr 2025

NewCVE-2025-3260  (opens in a new tab)
CWE-281  (opens in a new tab)

How to fix?

Upgrade github.com/grafana/grafana/pkg/api/pluginproxy to version 11.6.0+security-01 or higher.

Overview

github.com/grafana/grafana/pkg/api/pluginproxy is an open-source platform for monitoring and observability.

Affected versions of this package are vulnerable to Improper Preservation of Permissions in the proxy routing behavior, which allows certain users to bypass dashboard-specific permissions. A user with the Viewer role can view all dashboards in their org, and a user with the Editor role can view, edit, or delete all dashboards in their org.

This vulnerability is exploitable by authenticated users as well as anonymously authenticated users if anonymous authentication is enabled.

Workaround

This vulnerability can be avoided by enabling network policies that block all inbound traffic to the following endpoints:

  • /apis/dashboard.grafana.app/v0alpha1

  • /apis/dashboard.grafana.app/v1alpha1

  • /apis/dashboard.grafana.app/v2alpha1

CVSS Base Scores

version 4.0
version 3.1