CVE-2023-3128

Published Jun 22, 2023

Last updated 11 days ago

Overview

Description
Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.
Source
security@grafana.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@grafana.com
CWE-290
nvd@nist.gov
CWE-290

Social media

Hype score
Not currently trending

Configurations