When using the Grafana Databricks Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, it  could result in  the wrong user identifier being used, and information for which the viewer is not authorized being returned.  This issue affects Grafana Databricks Datasource Plugin: from 1.12.1 before 1.12.0
History

Wed, 12 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Nov 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Grafana
Grafana grafana
Vendors & Products Grafana
Grafana grafana

Tue, 11 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
Description When using the Grafana Databricks Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, it  could result in  the wrong user identifier being used, and information for which the viewer is not authorized being returned.  This issue affects Grafana Databricks Datasource Plugin: from 1.12.1 before 1.12.0
Title Incorrect oauth passthrough in Grafana Snowflake Datasource
Weaknesses CWE-653
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GRAFANA

Published:

Updated: 2025-11-12T21:45:13.287Z

Reserved: 2025-04-16T09:19:26.443Z

Link: CVE-2025-41116

cve-icon Vulnrichment

Updated: 2025-11-12T21:45:00.878Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-11T21:15:38.800

Modified: 2025-11-12T16:19:12.850

Link: CVE-2025-41116

cve-icon Redhat

No data.