VDB
CVE-2023-6152
CVE-2023-6152
PUBLISHED
CVSS 5.400000095367432 MEDIUM
A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only on sign up.
EPSS 1.38% · 70.4th percentile
Risk Scores
CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
EPSS Score
1.38%
70.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | grafana | 10.3.0, 2.5.0, 10.0.0 |
| Bitnami | grafana | 2.5.0, 10.0.0, 10.1.0 |
Timeline
- Feb 13, 2024 CVE Published
- Feb 13, 2024 PoC Published
- Feb 13, 2024 PoC Published
- Feb 14, 2024 EPSS Score
- Mar 12, 2024 EPSS Score
- Apr 9, 2024 EPSS Score
- Apr 12, 2024 PoC Published
- May 6, 2024 EPSS Score
- Jun 2, 2024 EPSS Score
- Jun 29, 2024 EPSS Score
- Jul 27, 2024 EPSS Score
- Aug 23, 2024 EPSS Score