Post
TechNadu
technadu.com
did:plc:ye4brpmgfvf4pkcwufgn2vu3
Grafana issued patches for CVE-2025-41115, a CVSS 10.0 SCIM flaw allowing impersonation or privilege escalation when certain SCIM settings were enabled.
The issue stems from numeric externalId values potentially conflicting with internal user IDs. Updated builds are now available.
#TechNews #Infosec
2025-11-22T18:02:59.535Z