CVE-2023-6152

MEDIUM

Grafana - Incorrect Authorization via Email Verification Bypass

Title source: llm
STIX 2.1

Description

A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only on sign up.

Scores

CVSS v3 5.4
EPSS 0.0138
EPSS Percentile 68.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (6)
grafana/grafana 10.0.0
grafana/grafana 10.1.0
grafana/grafana 10.2.0
grafana/grafana 10.3.0
grafana/grafana < 2.5.0
grafana/grafana 2.5.0 - 9.5.16Go
Published Feb 13, 2024
Tracked Since Feb 18, 2026