<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">CVE-2025-4123</DocumentTitle>
  <DocumentType>SUSE CVE</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE CVE-2025-4123</ID>
    </Identification>
    <Status>Interim</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>13</Number>
        <Date>2026-03-05T01:32:16Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2025-05-20T23:15:19Z</InitialReleaseDate>
    <CurrentReleaseDate>2026-03-05T01:32:16Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf-cve.pl</Engine>
      <Date>2020-12-27T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="CVE" Type="Summary" Ordinal="1" xml:lang="en">CVE-2025-4123</Note>
    <Note Title="Mitre CVE Description" Type="Description" Ordinal="2" xml:lang="en">A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF.

The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="4" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/suse-liberty-linux-updates/2025-June/001551.html</URL>
      <Description>E-Mail link for RHSA-2025:7893</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/suse-liberty-linux-updates/2025-May/001149.html</URL>
      <Description>E-Mail link for RHSA-2025:7894</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-updates/2025-June/040353.html</URL>
      <Description>E-Mail link for SUSE-SU-2025:01985-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/NUT27N46T3RCYUKKZDD2PQ3C7X7OURLR/</URL>
      <Description>E-Mail link for openSUSE-SU-2025:15179-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="Image SL-Micro">
      <Branch Type="Product Name" Name="Image SL-Micro">
        <FullProductName ProductID="Image SL-Micro">Image SL-Micro</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SL-Micro-Base">
      <Branch Type="Product Name" Name="Image SL-Micro-Base">
        <FullProductName ProductID="Image SL-Micro-Base">Image SL-Micro-Base</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SL-Micro-Base-RT">
      <Branch Type="Product Name" Name="Image SL-Micro-Base-RT">
        <FullProductName ProductID="Image SL-Micro-Base-RT">Image SL-Micro-Base-RT</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SL-Micro-Base-RT-SelfInstall">
      <Branch Type="Product Name" Name="Image SL-Micro-Base-RT-SelfInstall">
        <FullProductName ProductID="Image SL-Micro-Base-RT-SelfInstall">Image SL-Micro-Base-RT-SelfInstall</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SL-Micro-Base-RT-encrypted">
      <Branch Type="Product Name" Name="Image SL-Micro-Base-RT-encrypted">
        <FullProductName ProductID="Image SL-Micro-Base-RT-encrypted">Image SL-Micro-Base-RT-encrypted</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SL-Micro-Base-SelfInstall">
      <Branch Type="Product Name" Name="Image SL-Micro-Base-SelfInstall">
        <FullProductName ProductID="Image SL-Micro-Base-SelfInstall">Image SL-Micro-Base-SelfInstall</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SL-Micro-Base-encrypted">
      <Branch Type="Product Name" Name="Image SL-Micro-Base-encrypted">
        <FullProductName ProductID="Image SL-Micro-Base-encrypted">Image SL-Micro-Base-encrypted</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SL-Micro-Base-qcow">
      <Branch Type="Product Name" Name="Image SL-Micro-Base-qcow">
        <FullProductName ProductID="Image SL-Micro-Base-qcow">Image SL-Micro-Base-qcow</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SL-Micro-Default">
      <Branch Type="Product Name" Name="Image SL-Micro-Default">
        <FullProductName ProductID="Image SL-Micro-Default">Image SL-Micro-Default</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SL-Micro-Default-SelfInstall">
      <Branch Type="Product Name" Name="Image SL-Micro-Default-SelfInstall">
        <FullProductName ProductID="Image SL-Micro-Default-SelfInstall">Image SL-Micro-Default-SelfInstall</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SL-Micro-Default-encrypted">
      <Branch Type="Product Name" Name="Image SL-Micro-Default-encrypted">
        <FullProductName ProductID="Image SL-Micro-Default-encrypted">Image SL-Micro-Default-encrypted</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SL-Micro-Default-qcow">
      <Branch Type="Product Name" Name="Image SL-Micro-Default-qcow">
        <FullProductName ProductID="Image SL-Micro-Default-qcow">Image SL-Micro-Default-qcow</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLE-Micro">
      <Branch Type="Product Name" Name="Image SLE-Micro">
        <FullProductName ProductID="Image SLE-Micro">Image SLE-Micro</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLE-Micro-Azure">
      <Branch Type="Product Name" Name="Image SLE-Micro-Azure">
        <FullProductName ProductID="Image SLE-Micro-Azure">Image SLE-Micro-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLE-Micro-BYOS">
      <Branch Type="Product Name" Name="Image SLE-Micro-BYOS">
        <FullProductName ProductID="Image SLE-Micro-BYOS">Image SLE-Micro-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLE-Micro-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLE-Micro-BYOS-Azure">
        <FullProductName ProductID="Image SLE-Micro-BYOS-Azure">Image SLE-Micro-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLE-Micro-BYOS-EC2">
      <Branch Type="Product Name" Name="Image SLE-Micro-BYOS-EC2">
        <FullProductName ProductID="Image SLE-Micro-BYOS-EC2">Image SLE-Micro-BYOS-EC2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLE-Micro-BYOS-GCE">
      <Branch Type="Product Name" Name="Image SLE-Micro-BYOS-GCE">
        <FullProductName ProductID="Image SLE-Micro-BYOS-GCE">Image SLE-Micro-BYOS-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLE-Micro-EC2">
      <Branch Type="Product Name" Name="Image SLE-Micro-EC2">
        <FullProductName ProductID="Image SLE-Micro-EC2">Image SLE-Micro-EC2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLE-Micro-GCE">
      <Branch Type="Product Name" Name="Image SLE-Micro-GCE">
        <FullProductName ProductID="Image SLE-Micro-GCE">Image SLE-Micro-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS">
      <Branch Type="Product Name" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS">
        <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS">Image SLES15-SP4-Manager-Server-4-3-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure">
        <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure">Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2">
      <Branch Type="Product Name" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2">
        <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2">Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE">
        <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE">Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Liberty Linux 8">
      <Branch Type="Product Name" Name="SUSE Liberty Linux 8">
        <FullProductName ProductID="SUSE Liberty Linux 8" CPE="cpe:/o:suse:sll:8">SUSE Liberty Linux 8</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Liberty Linux 9">
      <Branch Type="Product Name" Name="SUSE Liberty Linux 9">
        <FullProductName ProductID="SUSE Liberty Linux 9" CPE="cpe:/o:suse:sll:9">SUSE Liberty Linux 9</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 16.0">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 16.0">
        <FullProductName ProductID="SUSE Linux Enterprise Server 16.0" CPE="cpe:/o:suse:sles:16:16.0:server">SUSE Linux Enterprise Server 16.0</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Server 4.3">
      <Branch Type="Product Name" Name="SUSE Manager Server 4.3">
        <FullProductName ProductID="SUSE Manager Server 4.3" CPE="cpe:/o:suse:suse-manager-server:4.3">SUSE Manager Server 4.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Multi-Linux Manager Client Tools for SLE 12">
      <Branch Type="Product Name" Name="SUSE Multi-Linux Manager Client Tools for SLE 12">
        <FullProductName ProductID="SUSE Multi-Linux Manager Client Tools for SLE 12" CPE="cpe:/o:suse:multi-linux-managertools-sle:12">SUSE Multi-Linux Manager Client Tools for SLE 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Multi-Linux Manager Client Tools for SLE 15">
      <Branch Type="Product Name" Name="SUSE Multi-Linux Manager Client Tools for SLE 15">
        <FullProductName ProductID="SUSE Multi-Linux Manager Client Tools for SLE 15" CPE="cpe:/o:suse:multi-linux-managertools-sle:15">SUSE Multi-Linux Manager Client Tools for SLE 15</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="gnutls-3.8.3-slfo.1.1_5.1">
      <FullProductName ProductID="gnutls-3.8.3-slfo.1.1_5.1" CPE="cpe:2.3:a:gnu:gnutls:3.8.3:*:*:*:*:*:*:*">gnutls-3.8.3-slfo.1.1_5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="govulncheck-vulndb-0.0.20250527T204717-1.1">
      <FullProductName ProductID="govulncheck-vulndb-0.0.20250527T204717-1.1">govulncheck-vulndb-0.0.20250527T204717-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="govulncheck-vulndb-0.0.20250814T182633-160000.1.2">
      <FullProductName ProductID="govulncheck-vulndb-0.0.20250814T182633-160000.1.2">govulncheck-vulndb-0.0.20250814T182633-160000.1.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grafana">
      <FullProductName ProductID="grafana" CPE="cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*">grafana</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grafana-10.2.6-13.el9_6">
      <FullProductName ProductID="grafana-10.2.6-13.el9_6" CPE="cpe:2.3:a:grafana:grafana:10.2.6:*:*:*:*:*:*:*">grafana-10.2.6-13.el9_6</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grafana-11.6.1+security01-1.1">
      <FullProductName ProductID="grafana-11.6.1+security01-1.1" CPE="cpe:2.3:a:grafana:grafana:11.6.1+security01:*:*:*:*:*:*:*">grafana-11.6.1+security01-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grafana-9.2.10-23.el8_10">
      <FullProductName ProductID="grafana-9.2.10-23.el8_10" CPE="cpe:2.3:a:grafana:grafana:9.2.10:*:*:*:*:*:*:*">grafana-9.2.10-23.el8_10</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grafana-selinux-10.2.6-13.el9_6">
      <FullProductName ProductID="grafana-selinux-10.2.6-13.el9_6">grafana-selinux-10.2.6-13.el9_6</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grafana-selinux-9.2.10-23.el8_10">
      <FullProductName ProductID="grafana-selinux-9.2.10-23.el8_10">grafana-selinux-9.2.10-23.el8_10</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgnutls30-3.8.3-slfo.1.1_5.1">
      <FullProductName ProductID="libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="release-notes-susemanager-4.3.15.2-150400.3.133.1">
      <FullProductName ProductID="release-notes-susemanager-4.3.15.2-150400.3.133.1">release-notes-susemanager-4.3.15.2-150400.3.133.1</FullProductName>
    </Branch>
    <Relationship ProductReference="gnutls-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SL-Micro">
      <FullProductName ProductID="Image SL-Micro:gnutls-3.8.3-slfo.1.1_5.1">gnutls-3.8.3-slfo.1.1_5.1 as a component of Image SL-Micro</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SL-Micro">
      <FullProductName ProductID="Image SL-Micro:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SL-Micro</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SL-Micro-Base">
      <FullProductName ProductID="Image SL-Micro-Base:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SL-Micro-Base</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SL-Micro-Base-RT">
      <FullProductName ProductID="Image SL-Micro-Base-RT:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SL-Micro-Base-RT</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SL-Micro-Base-RT-SelfInstall">
      <FullProductName ProductID="Image SL-Micro-Base-RT-SelfInstall:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SL-Micro-Base-RT-SelfInstall</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SL-Micro-Base-RT-encrypted">
      <FullProductName ProductID="Image SL-Micro-Base-RT-encrypted:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SL-Micro-Base-RT-encrypted</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SL-Micro-Base-SelfInstall">
      <FullProductName ProductID="Image SL-Micro-Base-SelfInstall:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SL-Micro-Base-SelfInstall</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SL-Micro-Base-encrypted">
      <FullProductName ProductID="Image SL-Micro-Base-encrypted:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SL-Micro-Base-encrypted</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SL-Micro-Base-qcow">
      <FullProductName ProductID="Image SL-Micro-Base-qcow:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SL-Micro-Base-qcow</FullProductName>
    </Relationship>
    <Relationship ProductReference="gnutls-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SL-Micro-Default">
      <FullProductName ProductID="Image SL-Micro-Default:gnutls-3.8.3-slfo.1.1_5.1">gnutls-3.8.3-slfo.1.1_5.1 as a component of Image SL-Micro-Default</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SL-Micro-Default">
      <FullProductName ProductID="Image SL-Micro-Default:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SL-Micro-Default</FullProductName>
    </Relationship>
    <Relationship ProductReference="gnutls-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SL-Micro-Default-SelfInstall">
      <FullProductName ProductID="Image SL-Micro-Default-SelfInstall:gnutls-3.8.3-slfo.1.1_5.1">gnutls-3.8.3-slfo.1.1_5.1 as a component of Image SL-Micro-Default-SelfInstall</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SL-Micro-Default-SelfInstall">
      <FullProductName ProductID="Image SL-Micro-Default-SelfInstall:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SL-Micro-Default-SelfInstall</FullProductName>
    </Relationship>
    <Relationship ProductReference="gnutls-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SL-Micro-Default-encrypted">
      <FullProductName ProductID="Image SL-Micro-Default-encrypted:gnutls-3.8.3-slfo.1.1_5.1">gnutls-3.8.3-slfo.1.1_5.1 as a component of Image SL-Micro-Default-encrypted</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SL-Micro-Default-encrypted">
      <FullProductName ProductID="Image SL-Micro-Default-encrypted:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SL-Micro-Default-encrypted</FullProductName>
    </Relationship>
    <Relationship ProductReference="gnutls-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SL-Micro-Default-qcow">
      <FullProductName ProductID="Image SL-Micro-Default-qcow:gnutls-3.8.3-slfo.1.1_5.1">gnutls-3.8.3-slfo.1.1_5.1 as a component of Image SL-Micro-Default-qcow</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SL-Micro-Default-qcow">
      <FullProductName ProductID="Image SL-Micro-Default-qcow:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SL-Micro-Default-qcow</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SLE-Micro">
      <FullProductName ProductID="Image SLE-Micro:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SLE-Micro</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SLE-Micro-Azure">
      <FullProductName ProductID="Image SLE-Micro-Azure:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SLE-Micro-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SLE-Micro-BYOS">
      <FullProductName ProductID="Image SLE-Micro-BYOS:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SLE-Micro-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SLE-Micro-BYOS-Azure">
      <FullProductName ProductID="Image SLE-Micro-BYOS-Azure:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SLE-Micro-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SLE-Micro-BYOS-EC2">
      <FullProductName ProductID="Image SLE-Micro-BYOS-EC2:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SLE-Micro-BYOS-EC2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SLE-Micro-BYOS-GCE">
      <FullProductName ProductID="Image SLE-Micro-BYOS-GCE:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SLE-Micro-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SLE-Micro-EC2">
      <FullProductName ProductID="Image SLE-Micro-EC2:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SLE-Micro-EC2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.8.3-slfo.1.1_5.1" RelationType="Default Component Of" RelatesToProductReference="Image SLE-Micro-GCE">
      <FullProductName ProductID="Image SLE-Micro-GCE:libgnutls30-3.8.3-slfo.1.1_5.1">libgnutls30-3.8.3-slfo.1.1_5.1 as a component of Image SLE-Micro-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="release-notes-susemanager-4.3.15.2-150400.3.133.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-Manager-Server-4-3-BYOS">
      <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS:release-notes-susemanager-4.3.15.2-150400.3.133.1">release-notes-susemanager-4.3.15.2-150400.3.133.1 as a component of Image SLES15-SP4-Manager-Server-4-3-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="release-notes-susemanager-4.3.15.2-150400.3.133.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure:release-notes-susemanager-4.3.15.2-150400.3.133.1">release-notes-susemanager-4.3.15.2-150400.3.133.1 as a component of Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="release-notes-susemanager-4.3.15.2-150400.3.133.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2">
      <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2:release-notes-susemanager-4.3.15.2-150400.3.133.1">release-notes-susemanager-4.3.15.2-150400.3.133.1 as a component of Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2</FullProductName>
    </Relationship>
    <Relationship ProductReference="release-notes-susemanager-4.3.15.2-150400.3.133.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE:release-notes-susemanager-4.3.15.2-150400.3.133.1">release-notes-susemanager-4.3.15.2-150400.3.133.1 as a component of Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="grafana-9.2.10-23.el8_10" RelationType="Default Component Of" RelatesToProductReference="SUSE Liberty Linux 8">
      <FullProductName ProductID="SUSE Liberty Linux 8:grafana-9.2.10-23.el8_10">grafana-9.2.10-23.el8_10 as a component of SUSE Liberty Linux 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="grafana-selinux-9.2.10-23.el8_10" RelationType="Default Component Of" RelatesToProductReference="SUSE Liberty Linux 8">
      <FullProductName ProductID="SUSE Liberty Linux 8:grafana-selinux-9.2.10-23.el8_10">grafana-selinux-9.2.10-23.el8_10 as a component of SUSE Liberty Linux 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="grafana-10.2.6-13.el9_6" RelationType="Default Component Of" RelatesToProductReference="SUSE Liberty Linux 9">
      <FullProductName ProductID="SUSE Liberty Linux 9:grafana-10.2.6-13.el9_6">grafana-10.2.6-13.el9_6 as a component of SUSE Liberty Linux 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="grafana-selinux-10.2.6-13.el9_6" RelationType="Default Component Of" RelatesToProductReference="SUSE Liberty Linux 9">
      <FullProductName ProductID="SUSE Liberty Linux 9:grafana-selinux-10.2.6-13.el9_6">grafana-selinux-10.2.6-13.el9_6 as a component of SUSE Liberty Linux 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="govulncheck-vulndb-0.0.20250814T182633-160000.1.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:govulncheck-vulndb-0.0.20250814T182633-160000.1.2">govulncheck-vulndb-0.0.20250814T182633-160000.1.2 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="release-notes-susemanager-4.3.15.2-150400.3.133.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 4.3">
      <FullProductName ProductID="SUSE Manager Server 4.3:release-notes-susemanager-4.3.15.2-150400.3.133.1">release-notes-susemanager-4.3.15.2-150400.3.133.1 as a component of SUSE Manager Server 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="govulncheck-vulndb-0.0.20250527T204717-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:govulncheck-vulndb-0.0.20250527T204717-1.1">govulncheck-vulndb-0.0.20250527T204717-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="grafana-11.6.1+security01-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:grafana-11.6.1+security01-1.1">grafana-11.6.1+security01-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="grafana" RelationType="Default Component Of" RelatesToProductReference="SUSE Multi-Linux Manager Client Tools for SLE 12">
      <FullProductName ProductID="SUSE Multi-Linux Manager Client Tools for SLE 12:grafana">grafana as a component of SUSE Multi-Linux Manager Client Tools for SLE 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="grafana" RelationType="Default Component Of" RelatesToProductReference="SUSE Multi-Linux Manager Client Tools for SLE 15">
      <FullProductName ProductID="SUSE Multi-Linux Manager Client Tools for SLE 15:grafana">grafana as a component of SUSE Multi-Linux Manager Client Tools for SLE 15</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF.

The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.</Note>
    </Notes>
    <CVE>CVE-2025-4123</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SL-Micro:gnutls-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro-Base:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro-Base-RT:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro-Base-RT-SelfInstall:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro-Base-RT-encrypted:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro-Base-SelfInstall:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro-Base-VMware:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro-Base-encrypted:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro-Base-qcow:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro-Default:gnutls-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro-Default:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro-Default-SelfInstall:gnutls-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro-Default-SelfInstall:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro-Default-VMware:gnutls-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro-Default-VMware:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro-Default-encrypted:gnutls-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro-Default-encrypted:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro-Default-qcow:gnutls-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SL-Micro-Default-qcow:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SLE-Micro:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SLE-Micro-Azure:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SLE-Micro-BYOS:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SLE-Micro-BYOS-Azure:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SLE-Micro-BYOS-EC2:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SLE-Micro-BYOS-GCE:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SLE-Micro-EC2:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SLE-Micro-GCE:libgnutls30-3.8.3-slfo.1.1_5.1</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-BYOS:release-notes-susemanager-4.3.15.2-150400.3.133.1</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure:release-notes-susemanager-4.3.15.2-150400.3.133.1</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2:release-notes-susemanager-4.3.15.2-150400.3.133.1</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE:release-notes-susemanager-4.3.15.2-150400.3.133.1</ProductID>
        <ProductID>SUSE Liberty Linux 8:grafana-9.2.10-23.el8_10</ProductID>
        <ProductID>SUSE Liberty Linux 8:grafana-selinux-9.2.10-23.el8_10</ProductID>
        <ProductID>SUSE Liberty Linux 9:grafana-10.2.6-13.el9_6</ProductID>
        <ProductID>SUSE Liberty Linux 9:grafana-selinux-10.2.6-13.el9_6</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:govulncheck-vulndb-0.0.20250814T182633-160000.1.2</ProductID>
        <ProductID>SUSE Manager Server 4.3:release-notes-susemanager-4.3.15.2-150400.3.133.1</ProductID>
        <ProductID>openSUSE Tumbleweed:govulncheck-vulndb-0.0.20250527T204717-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:grafana-11.6.1+security01-1.1</ProductID>
      </Status>
      <Status Type="Known Not Affected">
        <ProductID>SUSE Multi-Linux Manager Client Tools for SLE 12:grafana</ProductID>
        <ProductID>SUSE Multi-Linux Manager Client Tools for SLE 15:grafana</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV3>
        <BaseScoreV3>7.6</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
  </Vulnerability>
</cvrfdoc>
