CVE-2025-4123 GadyPrime/grafana_mythos_cve-2025-4123
影响攻击者可跨站脚本执行并可能读取敏感数据
CVE-2025-4123 是 Grafana 中的一个高危漏洞,公开信息显示其与跨站脚本(XSS)相关。攻击者可能通过构造恶意请求在用户浏览器中执行脚本,进而窃取会话或敏感信息。目前公开细节有限,具体利用链需参考官方公告。
影响范围
受影响版本范围暂无公开信息,建议以 Grafana 官方安全公告为准。
漏洞详情
该漏洞属于跨站脚本类型,成因可能是 Grafana 对用户输入或 URL 参数过滤不严,导致恶意脚本被注入页面。攻击者诱导已登录用户访问特制链接后,脚本可在受害者浏览器上下文中执行。目前公开的 GitHub 仓库仅为 PoC 或复现项目,未披露完整技术细节。
利用条件与风险
利用通常需要诱导用户点击恶意链接或访问受控页面,实战中可导致会话劫持或信息泄露。由于 Grafana 常用于监控敏感数据,风险较高。
修复建议
建议关注 Grafana 官方安全公告并升级至修复版本;临时可限制未授权访问、启用 CSP 等缓解措施。具体修复版本暂无公开信息。
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF.
The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.