Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2023-3128
HistoryJun 22, 2023 - 9:15 p.m.

CVE-2023-3128

2023-06-2221:15:00
Alpine Linux Development Team
security.alpinelinux.org
97
grafana
azure ad
email validation
account takeover
authentication bypass

0.001 Low

EPSS

Percentile

51.3%

Grafana is validating Azure AD accounts based on the email claim.

On Azure AD, the profile email field is not unique and can be easily modified.

This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

OSVersionArchitecturePackageVersionFilename
Alpine3.18-communitynoarchgrafana= 9.5.2-r4UNKNOWN