github.com
https://github.com/grafana/bugbounty/security/advisories/GHSA-3hv4-r2fm-h27f CVE-2023-6152
MEDIUM
Email Validation Bypass And Preventing Sign Up From Email's Owner
Record summary
CVE-2023-6152 has a selected CVSS score of 5.4 (medium).
Description
A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only on sign up.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 22, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
GrafanaBrowse Grafana / GrafanaDefault status: unknown | CVE List | 2.5.0 to < 9.5.16 | affected |
| 10.0.0 to < 10.0.11 | affected | ||
| 10.1.0 to < 10.1.7 | affected | ||
| 10.2.0 to < 10.2.4 | affected | ||
| 10.3.0 to < 10.3.3 | affected | ||
| 10.10 to < 10.1.7 | affected | ||
Grafana EnterpriseBrowse Grafana / Grafana EnterpriseDefault status: unknown | CVE List | 2.5.0 to < 9.5.16 | affected |
| 10.0.0 to < 10.0.11 | affected | ||
| 10.1.0 to < 10.1.7 | affected | ||
| 10.2.0 to < 10.2.4 | affected | ||
| 10.3.0 to < 10.3.3 | affected | ||
| 10.10 to < 10.1.7 | affected | ||
github.com/grafana/grafanaBrowse Go / github.com/grafana/grafana | GitHub Advisory | 2.5.0 to < 9.5.16 · Fixed in 9.5.16 | affected |
| 10.0.0 to < 10.0.11 · Fixed in 10.0.11 | affected | ||
| 10.1.0 to < 10.1.7 · Fixed in 10.1.7 | affected | ||
| 10.2.0 to < 10.2.4 · Fixed in 10.2.4 | affected | ||
| 10.3.0 to < 10.3.3 · Fixed in 10.3.3 | affected |
References
5github.com
https://github.com/grafana/grafana grafana.com
https://grafana.com/security/security-advisories/cve-2023-6152 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-6152 security.netapp.com
https://security.netapp.com/advisory/ntap-20250214-0008