Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-3128

Опубликовано: 22 июн. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.4

Описание

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

РелизСтатусПримечание
devel

DNE

esm-apps/xenial

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 79%
0.01394
Низкий

9.4 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
redhat
почти 2 года назад

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

CVSS3: 9.4
nvd
почти 2 года назад

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

CVSS3: 9.4
debian
почти 2 года назад

Grafana is validating Azure AD accounts based on the email claim. On ...

rocky
почти 2 года назад

Critical: grafana security update

CVSS3: 9.4
github
почти 2 года назад

Grafana vulnerable to Authentication Bypass by Spoofing

EPSS

Процентиль: 79%
0.01394
Низкий

9.4 Critical

CVSS3