Record summary

CVE-2023-6152 has a selected CVSS score of 5.4 (medium).

Description

A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only on sign up.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 22, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: unknown

CVE List2.5.0 to < 9.5.16affected
10.0.0 to < 10.0.11affected
10.1.0 to < 10.1.7affected
10.2.0 to < 10.2.4affected
10.3.0 to < 10.3.3affected
10.10 to < 10.1.7affected

Default status: unknown

CVE List2.5.0 to < 9.5.16affected
10.0.0 to < 10.0.11affected
10.1.0 to < 10.1.7affected
10.2.0 to < 10.2.4affected
10.3.0 to < 10.3.3affected
10.10 to < 10.1.7affected

github.com/grafana/grafana

Browse Go / github.com/grafana/grafana
GitHub Advisory2.5.0 to < 9.5.16 · Fixed in 9.5.16affected
10.0.0 to < 10.0.11 · Fixed in 10.0.11affected
10.1.0 to < 10.1.7 · Fixed in 10.1.7affected
10.2.0 to < 10.2.4 · Fixed in 10.2.4affected
10.3.0 to < 10.3.3 · Fixed in 10.3.3affected

References

5