CRITICAL 9.4 Go
Grafana vulnerable to Authentication Bypass by Spoofing
GHSA-mpv3-g8m3-3fjc · BIT-grafana-2023-3128 · CVE-2023-3128 · GHSA-gxh2-6vvc-rrgp
Published · Modified
Description
Grafana is validating Azure AD accounts based on the email claim.
On Azure AD, the profile email field is not unique and can be easily modified.
This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.
References
- WEB https://github.com/grafana/bugbounty/security/advisories/GHSA-gxh2-6vvc-rrgp
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2023-3128
- PACKAGE https://github.com/grafana/grafana
- WEB https://github.com/grafana/grafana/blob/69fc4e6bc0be2a82085ab3885c2262a4d49e97d8/CHANGELOG.md
- WEB https://grafana.com/security/security-advisories/cve-2023-3128
- WEB https://security.netapp.com/advisory/ntap-20230714-0004
Ready to move
Start Securing
Free, no credit card | First findings in minutes