CVE-2023-3128: Critical severity Grafana Grafana vulnerability
Grafana is validating Azure AD accounts based on the email claim.
On Azure AD, the profile email field is not unique and can be easily modified.
This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.
Other sources
Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique across Azure AD tenants. This enables Grafana account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant AzureAD OAuth application. If exploited, the attacker can gain complete control of the user's account, including access to private customer data and sensitive information. All users in Grafana deployments with Azure AD OAuth configured with a multi-tenant Azure app and which do not have allowedgroups configured are affected and can be compromised.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/grafana/grafanato a version that resolves this vulnerability.Fixed in 8.5.27 - Upgrade
Upgrade
go/github.com/grafana/grafanato a version that resolves this vulnerability.Fixed in 9.2.20 - Upgrade
Upgrade
go/github.com/grafana/grafanato a version that resolves this vulnerability.Fixed in 9.3.16 - Upgrade
Upgrade
go/github.com/grafana/grafanato a version that resolves this vulnerability.Fixed in 9.4.13 - Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 10.0.0 - Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 9.5.4 - Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 9.4.13 - Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 9.3.16 - Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 9.2.20 - Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 8.5.27
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-3128.
What is the severity of CVE-2023-3128?
The severity of CVE-2023-3128 is critical (severity value: 9).
How does CVE-2023-3128 affect Grafana?
CVE-2023-3128 affects Grafana by allowing account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.
Which versions of Grafana are affected by CVE-2023-3128?
Versions 6.7.0 to 8.5.27 are affected by CVE-2023-3128.
How can I fix CVE-2023-3128?
To fix CVE-2023-3128, update Grafana to version 8.5.27 or apply the relevant security patches provided by Grafana.