CVE-2025-41116
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-11

Last updated on: 2025-11-19

Assigner: Grafana Labs

Description
When using the Grafana Databricks Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, itΒ  could result inΒ  the wrong user identifier being used, and information for which the viewer is not authorized being returned.Β  This issue affects Grafana Databricks Datasource Plugin: from 1.6.0 before 1.12.0
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-11
Last Modified
2025-11-19
Generated
2026-05-07
AI Q&A
2025-11-11
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
grafana databricks_datasource_plugin 1.6.0
grafana databricks_datasource_plugin 1.12.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-653 The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability occurs in the Grafana Databricks Datasource Plugin when OAuth passthrough is enabled and multiple users access the same datasource simultaneously on a single Grafana instance. It can cause the wrong user identifier to be used, leading to information being returned to a viewer who is not authorized to see it.


How can this vulnerability impact me? :

The vulnerability can result in unauthorized access to information because the system may return data associated with the wrong user. This means sensitive or private information could be exposed to users who should not have access to it.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart