The vendor explicitly states that these products are not affected by this CVE.
- multicluster-globalhub/multicluster-globalhub-grafana-rhel9 as a component of Multicluster Global Hub
- rhacm2/acm-grafana-rhel9 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- rhceph/rhceph-5-dashboard-rhel8 as a component of Red Hat Ceph Storage 5
- rhceph/rhceph-6-dashboard-rhel9 as a component of Red Hat Ceph Storage 6
- rhceph/grafana-rhel9 as a component of Red Hat Ceph Storage 7
- rhceph/grafana-rhel9 as a component of Red Hat Ceph Storage 8
- rhceph/grafana-rhel10 as a component of Red Hat Ceph Storage 9
- grafana as a component of Red Hat Enterprise Linux 10
- grafana-selinux as a component of Red Hat Enterprise Linux 10
- grafana.src as a component of Red Hat Enterprise Linux 10
- grafana as a component of Red Hat Enterprise Linux 8
- grafana-azure-monitor as a component of Red Hat Enterprise Linux 8
- Summary
- On Grafana Enterprise instances with the optional IdP-initiated SAML single sign-on enabled (allow_idp_initiated = true, disabled by default), Grafana did not fully validate the InResponseTo field of SAML responses. An attacker who obtained a valid, signed SAML assertion for a user could replay it within its short validity window to obtain an authenticated session as that user.
- Remediation
- No remediation text is recorded.
