CVE-2025-3717
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-11-11
Last updated on: 2025-11-11
Assigner: Grafana Labs
Description
Description
When using the Grafana Snowflake Datasource Plugin,
if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, itΒ could result inΒ
the wrong user identifier being used, and information for which the viewer is not authorized being returned.Β
This issue affects Grafana Snowflake Datasource Plugin: from 1.5.0 before 1.14.1.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| grafana | snowflake_datasource_plugin | 1.5.0 |
| grafana | snowflake_datasource_plugin | 1.14.1 |
| grafana | snowflake_datasource_plugin | 1.14.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-653 | The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions. |