Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-3128
HistoryJun 22, 2023 - 9:15 p.m.

Authentication flaw

2023-06-2221:15:00
PRIOn knowledge base
www.prio-n.com
7
grafana
azure ad
account validation
email claim
profile field
unique
modified
account takeover
authentication bypass
oauth
multi-tenant app

9.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

51.3%

Grafana is validating Azure AD accounts based on the email claim.

On Azure AD, the profile email field is not unique and can be easily modified.

This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.