CVE-2023-3128

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*

History

21 Jul 2023, 19:19

Type Values Removed Values Added
References (MISC) https://security.netapp.com/advisory/ntap-20230714-0004/ - (MISC) https://security.netapp.com/advisory/ntap-20230714-0004/ - Third Party Advisory
References (MISC) https://github.com/grafana/bugbounty/security/advisories/GHSA-gxh2-6vvc-rrgp - (MISC) https://github.com/grafana/bugbounty/security/advisories/GHSA-gxh2-6vvc-rrgp - Vendor Advisory

18 Jul 2023, 08:15

Type Values Removed Values Added
References
  • (MISC) https://security.netapp.com/advisory/ntap-20230714-0004/ -

06 Jul 2023, 09:15

Type Values Removed Values Added
References
  • (MISC) https://github.com/grafana/bugbounty/security/advisories/GHSA-gxh2-6vvc-rrgp -

30 Jun 2023, 17:49

Type Values Removed Values Added
First Time Grafana
Grafana grafana
CWE CWE-290
References (MISC) https://grafana.com/security/security-advisories/cve-2023-3128/ - (MISC) https://grafana.com/security/security-advisories/cve-2023-3128/ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*

22 Jun 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-22 21:15

Updated : 2024-02-28 20:13


NVD link : CVE-2023-3128

Mitre link : CVE-2023-3128

CVE.ORG link : CVE-2023-3128


JSON object : View

Products Affected

grafana

  • grafana
CWE
CWE-290

Authentication Bypass by Spoofing