CVE-2025-6197
50Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendcvss 4.2epss 72%
probabilidade de exploração
72%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
O que os fabricantes declaram (VEX)
Declarações oficiais dos fabricantes em formato CSAF/VEX: se o produto deles está afetado, já corrigido ou descartado — e por quê. É afirmação do fabricante, não juízo do Vexday.
Red Hatdocumento VEX ↗
Afetado
3 produtos (21 componentes)
Red Hat Enterprise Linux 8 · Red Hat Enterprise Linux 10 · Red Hat Enterprise Linux 9
workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
An open redirect vulnerability has been identified in Grafana OSS organization switching functionality.
Prerequisites for exploitation:
- Multiple organizations must exist in the Grafana instance
- Victim must be on a different organization than the one specified in the URL
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Produtos afetados
Grafana · Grafana