Vulnerability Description
When using the Grafana Snowflake Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, it could result in the wrong user identifier being used, and information for which the viewer is not authorized being returned. This issue affects Grafana Snowflake Datasource Plugin: from 1.5.0 before 1.14.1.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-3717?
CVE-2025-3717 is a documented vulnerability. When using the Grafana Snowflake Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, i...
How severe is CVE-2025-3717?
CVSS scoring is not yet available for CVE-2025-3717. Check NVD for updates.
Is there a patch for CVE-2025-3717?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.