A user changing their email after signing up and verifying it can change it without verification in profile settings.
The configuration option "verify_email_enabled" will only validate email only on sign up.
The configuration option "verify_email_enabled" will only validate email only on sign up.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0487 | A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only on sign up. |
Github GHSA |
GHSA-3hv4-r2fm-h27f | Email Validation Bypass And Preventing Sign Up From Email's Owner |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 15 Feb 2025 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 15 Feb 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Grafana grafana Enterprise
|
|
| CPEs | cpe:2.3:a:grafana:grafana_enterprise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Grafana grafana Enterprise
|
|
| Metrics |
ssvc
|
Mon, 21 Oct 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Grafana
Grafana grafana |
|
| CPEs | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* cpe:2.3:a:grafana:grafana:10.0.0:*:*:*:*:*:*:* cpe:2.3:a:grafana:grafana:10.1.0:*:*:*:*:*:*:* cpe:2.3:a:grafana:grafana:10.2.0:*:*:*:*:*:*:* cpe:2.3:a:grafana:grafana:10.3.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Grafana
Grafana grafana |
Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2025-02-15T00:10:28.890Z
Reserved: 2023-11-15T12:44:28.824Z
Link: CVE-2023-6152
Updated: 2025-02-15T00:10:28.890Z
Status : Modified
Published: 2024-02-13T22:15:45.430
Modified: 2025-02-15T01:15:09.723
Link: CVE-2023-6152
OpenCVE Enrichment
No data.
EUVD
Github GHSA