CVE-2020-27846: Critical severity Grafana Grafana vulnerability
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Other sources
A vulnerability exist in the github.com/crewjam/saml library used Grafana to process SAML Authentication. A Grafana instance configured to use SAML Authentication is vulnerable to this issue. An attacker can use this flaw to bypass authentication in Grafana.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-27846?
CVE-2020-27846 is a signature verification vulnerability in crewjam/saml that allows bypassing of SAML Authentication.
What is the severity of CVE-2020-27846?
CVE-2020-27846 has a severity value of 9, which is considered critical.
How does CVE-2020-27846 impact affected software?
CVE-2020-27846 can lead to confidentiality, integrity, and system availability issues in the affected software.
Which software versions are affected by CVE-2020-27846?
The affected software versions include grafana 0:7.3.6-2.el8, 7.3.6, 7.2.3, 6.7.5, and github.com/crewjam/saml 0.4.3.
How can I fix CVE-2020-27846?
To fix CVE-2020-27846, update the affected software to the recommended versions: grafana 7.3.6-2.el8, 7.3.6, 7.2.3, 6.7.5, and github.com/crewjam/saml 0.4.3.