Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-3128

Опубликовано: 22 июн. 2023
Источник: ubuntu
Приоритет: medium
CVSS3: 9.4

Описание

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

РелизСтатусПримечание
devel

DNE

esm-apps/xenial

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

questing

DNE

upstream

needs-triage

Показывать по

Ссылки на источники

9.4 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
redhat
больше 2 лет назад

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

CVSS3: 9.4
nvd
больше 2 лет назад

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

CVSS3: 9.4
debian
больше 2 лет назад

Grafana is validating Azure AD accounts based on the email claim. On ...

rocky
больше 2 лет назад

Critical: grafana security update

CVSS3: 9.4
github
больше 2 лет назад

Grafana vulnerable to Authentication Bypass by Spoofing

9.4 Critical

CVSS3