CVE-2023-6152
13.02.2024, 22:15
A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only on sign up.Enginsight
Vendor | Product | Version |
---|---|---|
grafana | grafana | 𝑥 ≤ 2.5.0 |
grafana | grafana | 10.0.0 |
grafana | grafana | 10.1.0 |
grafana | grafana | 10.2.0 |
grafana | grafana | 10.3.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References