← back
CVE-2025-6197mediumCWE-601

CVE-2025-6197

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 4.2epss 72%
exploitation probability
72%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
3 products (21 components)
Red Hat Enterprise Linux 8 · Red Hat Enterprise Linux 10 · Red Hat Enterprise Linux 9
workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected products
Grafana · Grafana