CVE-2023-3128

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/06/2023
Last modified:
13/02/2025

Description

Grafana is validating Azure AD accounts based on the email claim. <br /> <br /> On Azure AD, the profile email field is not unique and can be easily modified. <br /> <br /> This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:* 6.7.0 (including) 8.5.27 (excluding)
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:* 6.7.0 (including) 8.5.27 (excluding)
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:* 9.2.0 (including) 9.2.20 (excluding)
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:* 9.2.0 (including) 9.2.20 (excluding)
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:* 9.3.0 (including) 9.3.16 (excluding)
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:* 9.3.0 (including) 9.3.16 (excluding)
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:* 9.4.0 (including) 9.4.13 (excluding)
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:* 9.4.0 (including) 9.4.13 (excluding)
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:* 9.5.0 (including) 9.5.4 (excluding)
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:* 9.5.0 (including) 9.5.4 (excluding)