CVE-2023-6152
Vulnerability Summary
Timeline
Description
A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only on sign up.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
EPSS Trends
Current EPSS score: 0.22%• Percentile: 45%
Techniques & Countermeasures
- CWE-863•Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Affected Systems
- github.com/grafana•grafana
≥ 2.5.0, < 9.5.16 | ≥ 10.0.0, < 10.0.11 | ≥ 10.1.0, < 10.1.7 | ≥ 10.2.0, < 10.2.4 | ≥ 10.3.0, < 10.3.3
- grafana•grafana
≥ 2.5.0, < 9.5.16 | ≥ 10.0.0, < 10.0.11 | ≥ 10.1.0, < 10.1.7 | ≥ 10.2.0, < 10.2.4 | ≥ 10.3.0, < 10.3.3 | ≤ 2.5.0 | 10.0.0 | 10.1.0 | 10.2.0 | 10.3.0
- grafana•grafana enterprise
≥ 2.5.0, < 9.5.16 | ≥ 10.0.0, < 10.0.11 | ≥ 10.1.0, < 10.1.7 | ≥ 10.2.0, < 10.2.4 | ≥ 10.3.0, < 10.3.3
References (7)
- https://grafana.com/security/security-advisories/cve-2023-6152/
- https://github.com/grafana/bugbounty/security/advisories/GHSA-3hv4-r2fm-h27f
- https://security.netapp.com/advisory/ntap-20250214-0008/
- https://nvd.nist.gov/vuln/detail/CVE-2023-6152
- https://github.com/grafana/grafana
- https://grafana.com/security/security-advisories/cve-2023-6152
- https://security.netapp.com/advisory/ntap-20250214-0008