VYPR
Moderate severityNVD Advisory· Published Feb 13, 2024· Updated Feb 15, 2025

CVE-2023-6152

CVE-2023-6152

Description

A user changing their email after signing up and verifying it can change it without verification in profile settings.

The configuration option "verify_email_enabled" will only validate email only on sign up.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/grafana/grafanaGo
>= 2.5.0, < 9.5.169.5.16
github.com/grafana/grafanaGo
>= 10.0.0, < 10.0.1110.0.11
github.com/grafana/grafanaGo
>= 10.1.0, < 10.1.710.1.7
github.com/grafana/grafanaGo
>= 10.2.0, < 10.2.410.2.4
github.com/grafana/grafanaGo
>= 10.3.0, < 10.3.310.3.3

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.