FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2025-08-01 09:57:49 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
310f5923-211c-11f0-8ca6-6c3be5272acdGrafana -- Authorization bypass in data source proxy API

Grafana Labs reports:

This vulnerability, which was discovered while reviewing a pull request from an external contributor, effects Grafana’s data source proxy API and allows authorization checks to be bypassed by adding an extra slash character (/) in the URL path. Among Grafana-maintained data sources, the vulnerability only affects the read paths of Prometheus (all flavors) and Alertmanager when configured with basic authorization.

The CVSS score for this vulnerability is 5.0 MEDIUM.


Discovery 2025-03-25
Entry 2025-04-24
grafana
>= 8.0.0 lt 10.4.17+security-01

>= 11.0.0 lt 11.2.8+security-01

>= 11.3.0 lt 11.3.5+security-01

>= 11.4.0 lt 11.4.3+security-01

>= 11.5.0 lt 11.5.3+security-01

>= 11.6.0 lt 11.6.0+security-01

grafana8
>= 8.0.0

grafana9
>= 9.0.0

CVE-2025-3454
https://grafana.com/blog/2025/04/22/grafana-security-release-medium-and-high-severity-fixes-for-cve-2025-3260-cve-2025-2703-cve-2025-3454/