Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mpv3-g8m3-3fjc

Опубликовано: 22 июн. 2023
Источник: github
Github: Прошло ревью
CVSS3: 9.4

Описание

Grafana vulnerable to Authentication Bypass by Spoofing

Grafana is validating Azure AD accounts based on the email claim.

On Azure AD, the profile email field is not unique and can be easily modified.

This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

Пакеты

Наименование

github.com/grafana/grafana

go
Затронутые версииВерсия исправления

>= 9.4.0, < 9.4.13

9.4.13

Наименование

github.com/grafana/grafana

go
Затронутые версииВерсия исправления

>= 9.3.0, < 9.3.16

9.3.16

Наименование

github.com/grafana/grafana

go
Затронутые версииВерсия исправления

>= 9.0.0, < 9.2.20

9.2.20

Наименование

github.com/grafana/grafana

go
Затронутые версииВерсия исправления

< 8.5.27

8.5.27

EPSS

Процентиль: 79%
0.01394
Низкий

9.4 Critical

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 9.4
ubuntu
почти 2 года назад

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

CVSS3: 9.8
redhat
почти 2 года назад

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

CVSS3: 9.4
nvd
почти 2 года назад

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

CVSS3: 9.4
debian
почти 2 года назад

Grafana is validating Azure AD accounts based on the email claim. On ...

rocky
почти 2 года назад

Critical: grafana security update

EPSS

Процентиль: 79%
0.01394
Низкий

9.4 Critical

CVSS3

Дефекты

CWE-290