Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-3128
Description:Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.
Test IDs: 1.3.6.1.4.1.25623.1.0.124342  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-3128
https://github.com/grafana/bugbounty/security/advisories/GHSA-gxh2-6vvc-rrgp
https://github.com/grafana/bugbounty/security/advisories/GHSA-gxh2-6vvc-rrgp
https://grafana.com/security/security-advisories/cve-2023-3128/
https://grafana.com/security/security-advisories/cve-2023-3128/




© 1998-2025 E-Soft Inc. All rights reserved.