The vendor explicitly identifies these products as affected by this CVE.
- servicemesh-grafana as a component of OpenShift Service Mesh 2.1
- servicemesh-grafana.src as a component of OpenShift Service Mesh 2.1
- grafana as a component of Red Hat Ceph Storage 3
- grafana.src as a component of Red Hat Ceph Storage 3
- rhceph/rhceph-4-dashboard-rhel8 as a component of Red Hat Ceph Storage 4
- rhceph/rhceph-5-dashboard-rhel8 as a component of Red Hat Ceph Storage 5
- rhceph/rhceph-6-dashboard-rhel9 as a component of Red Hat Ceph Storage 6
- rhceph/grafana-rhel10 as a component of Red Hat Ceph Storage 7
- rhceph/grafana-rhel9 as a component of Red Hat Ceph Storage 7
- grafana as a component of Red Hat Enterprise Linux 8
- grafana-azure-monitor as a component of Red Hat Enterprise Linux 8
- grafana-cloudwatch as a component of Red Hat Enterprise Linux 8
- Summary
- An authentication bypass vulnerability was found in the verify_email_enabled feature of Grafana. Even when enabled, this configuration option does not fully enforce email verification. This issue could allow a remote attacker that has authenticated with basic credentials to change the email address to use an unverified address. Successful exploitation could allow evasion of an organization's email domain filtering rules. An example of this is permitting a user in blocklisted countries or service providers to utilize a service.
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
