Impact
The revised CVE description confirms a path traversal vulnerability in the Tempo and Loki data source plugins. A user with Viewer permissions can craft specially designed requests that reach unintended backend endpoints. Depending on the backend configuration, this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.
Affected Systems
Any Grafana OSS installation that includes the Tempo and Loki plugins is potentially affected. Grafana versions, so administrators should assume the vulnerability exists in all unpatched instances of these plugins.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity while the EPSS score of less than 1% and absence from the CISA KEV catalog suggest that the vulnerability is not widely exploited at present. The attack requires a legitimate Viewer‑level account that can send API requests through the Grafana interface; by manipulating request parameters a threat actor can reach protected backend endpoints, potentially exfiltrating credentials or initiating state‑changing operations on the Tempo or Loki services.
OpenCVE Enrichment