<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 17:57:10 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:4030 — Critical: grafana security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:4030</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp; OpenTSDB.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* grafana: account takeover possible when using Azure AD OAuth (CVE-2023-3128)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp; OpenTSDB.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* grafana: account takeover possible when using Azure AD OAuth (CVE-2023-3128)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:4030</guid>
    </item>
    <item>
      <title>bdu:2023-03343</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03343</link>
      <description>bdu:2023-03343</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03343</guid>
    </item>
    <item>
      <title>BIT-grafana-2023-3128</title>
      <link>https://cve.radiocsirt.org/vuln/bit-grafana-2023-3128</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: grafana&lt;/p&gt;
&lt;p&gt;Grafana is validating Azure AD accounts based on the email claim.&lt;/p&gt;
&lt;p&gt;On Azure AD, the profile email field is not unique and can be easily modified.&lt;/p&gt;
&lt;p&gt;This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: grafana&lt;/p&gt;
&lt;p&gt;Grafana is validating Azure AD accounts based on the email claim.&lt;/p&gt;
&lt;p&gt;On Azure AD, the profile email field is not unique and can be easily modified.&lt;/p&gt;
&lt;p&gt;This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-grafana-2023-3128</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0497 — De multiples vulnérabilités ont été découvertes dans Grafana. Elles
permettent à un attaquant de provoquer un contourne…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0497</link>
      <description>certfr-2023-avi-0497</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0497</guid>
    </item>
    <item>
      <title>EUVD-2026-216449</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-216449</link>
      <description>EUVD-2026-216449</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-216449</guid>
    </item>
    <item>
      <title>fkie_cve-2023-3128</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-3128</link>
      <description>&lt;p&gt;Grafana is validating Azure AD accounts based on the email claim.&lt;/p&gt;
&lt;p&gt;On Azure AD, the profile email field is not unique and can be easily modified.&lt;/p&gt;
&lt;p&gt;This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Grafana is validating Azure AD accounts based on the email claim.&lt;/p&gt;
&lt;p&gt;On Azure AD, the profile email field is not unique and can be easily modified.&lt;/p&gt;
&lt;p&gt;This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-3128</guid>
    </item>
    <item>
      <title>GHSA-mpv3-g8m3-3fjc — Grafana vulnerable to Authentication Bypass by Spoofing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mpv3-g8m3-3fjc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/grafana/grafana&lt;/p&gt;
&lt;p&gt;Grafana is validating Azure AD accounts based on the email claim.&lt;/p&gt;
&lt;p&gt;On Azure AD, the profile email field is not unique and can be easily modified.&lt;/p&gt;
&lt;p&gt;This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/grafana/grafana&lt;/p&gt;
&lt;p&gt;Grafana is validating Azure AD accounts based on the email claim.&lt;/p&gt;
&lt;p&gt;On Azure AD, the profile email field is not unique and can be easily modified.&lt;/p&gt;
&lt;p&gt;This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mpv3-g8m3-3fjc</guid>
    </item>
    <item>
      <title>gsd-2023-3128</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-3128</link>
      <description>gsd-2023-3128</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-3128</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13018-1 — grafana-10.0.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13018-1</link>
      <description>&lt;p&gt;grafana-10.0.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;grafana-10.0.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13018-1</guid>
    </item>
    <item>
      <title>RHSA-2024:3925 — Red Hat Security Advisory: Red Hat Ceph Storage 7.1 security, enhancements, and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:3925</link>
      <description>&lt;p&gt;grafana: account takeover possible when using Azure AD OAuth grafana: incorrect assessment of permissions across organizations go-git: Maliciously crafted Git server replies can cause DoS on go-git clients go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;grafana: account takeover possible when using Azure AD OAuth grafana: incorrect assessment of permissions across organizations go-git: Maliciously crafted Git server replies can cause DoS on go-git clients go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:3925</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:2915-1 — Security update for SUSE Manager Client Tools</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:2915-1</link>
      <description>&lt;p&gt;Security update for SUSE Manager Client Tools&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for SUSE Manager Client Tools&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:2915-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-3128</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-3128</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grafana&lt;/p&gt;
&lt;p&gt;Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grafana&lt;/p&gt;
&lt;p&gt;Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-3128</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1551 — Grafana: Schwachstelle ermöglicht Übernahme von Benutzerkonto</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1551</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Grafana ausnutzen, um ein Benutzerkonto zu übernehmen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Grafana ausnutzen, um ein Benutzerkonto zu übernehmen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1551</guid>
    </item>
  </channel>
</rss>
