When using the Grafana Snowflake Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, it  could result in  the wrong user identifier being used, and information for which the viewer is not authorized being returned.  This issue affects Grafana Snowflake Datasource Plugin: from 1.5.0 before 1.14.1.
History

Wed, 12 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Nov 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Grafana
Grafana grafana
Vendors & Products Grafana
Grafana grafana

Tue, 11 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
Description When using the Grafana Snowflake Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, it  could result in  the wrong user identifier being used, and information for which the viewer is not authorized being returned.  This issue affects Grafana Snowflake Datasource Plugin: from 1.5.0 before 1.14.1.
Title Incorrect oauth passthrough in Grafana Snowflake Datasource
Weaknesses CWE-653
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GRAFANA

Published:

Updated: 2025-11-12T21:46:15.867Z

Reserved: 2025-04-16T08:56:42.388Z

Link: CVE-2025-3717

cve-icon Vulnrichment

Updated: 2025-11-12T21:46:12.827Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-11T21:15:37.290

Modified: 2025-11-12T16:19:12.850

Link: CVE-2025-3717

cve-icon Redhat

No data.