CVE-2025-3717
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-11

Last updated on: 2025-11-11

Assigner: Grafana Labs

Description
When using the Grafana Snowflake Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, itΒ  could result inΒ  the wrong user identifier being used, and information for which the viewer is not authorized being returned.Β  This issue affects Grafana Snowflake Datasource Plugin: from 1.5.0 before 1.14.1.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-11
Last Modified
2025-11-11
Generated
2026-05-07
AI Q&A
2025-11-11
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
grafana snowflake_datasource_plugin 1.5.0
grafana snowflake_datasource_plugin 1.14.1
grafana snowflake_datasource_plugin 1.14.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-653 The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability occurs in the Grafana Snowflake Datasource Plugin when Oauth passthrough is enabled and multiple users use the same datasource simultaneously on a single Grafana instance. It can cause the wrong user identifier to be used, potentially returning information to a user that they are not authorized to see.


How can this vulnerability impact me? :

The vulnerability can lead to unauthorized information disclosure, where a user might see data belonging to another user due to incorrect user identification in the datasource plugin.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, update the Grafana Snowflake Datasource Plugin to version 1.14.1 or later, as versions from 1.5.0 before 1.14.1 are affected. Additionally, consider disabling Oauth passthrough on the datasource if multiple users share the same datasource on a single Grafana instance until the update is applied.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart