CVE-2023-3128

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*

History

13 Feb 2025, 17:16

Type Values Removed Values Added
Summary (en) Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app. (en) Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

21 Nov 2024, 08:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 9.4
References () https://github.com/grafana/bugbounty/security/advisories/GHSA-gxh2-6vvc-rrgp - Vendor Advisory () https://github.com/grafana/bugbounty/security/advisories/GHSA-gxh2-6vvc-rrgp - Vendor Advisory
References () https://grafana.com/security/security-advisories/cve-2023-3128/ - Vendor Advisory () https://grafana.com/security/security-advisories/cve-2023-3128/ - Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20230714-0004/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20230714-0004/ - Third Party Advisory

21 Jul 2023, 19:19

Type Values Removed Values Added
References (MISC) https://github.com/grafana/bugbounty/security/advisories/GHSA-gxh2-6vvc-rrgp - (MISC) https://github.com/grafana/bugbounty/security/advisories/GHSA-gxh2-6vvc-rrgp - Vendor Advisory
References (MISC) https://security.netapp.com/advisory/ntap-20230714-0004/ - (MISC) https://security.netapp.com/advisory/ntap-20230714-0004/ - Third Party Advisory

18 Jul 2023, 08:15

Type Values Removed Values Added
References
  • (MISC) https://security.netapp.com/advisory/ntap-20230714-0004/ -

06 Jul 2023, 09:15

Type Values Removed Values Added
References
  • (MISC) https://github.com/grafana/bugbounty/security/advisories/GHSA-gxh2-6vvc-rrgp -

30 Jun 2023, 17:49

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-22 21:15

Updated : 2025-02-13 17:16


NVD link : CVE-2023-3128

Mitre link : CVE-2023-3128

CVE.ORG link : CVE-2023-3128


JSON object : View

Products Affected

grafana

  • grafana
CWE
CWE-290

Authentication Bypass by Spoofing