Total vulnerabilities in the database
A user changing their email after signing up and verifying it can change it without verification in profile settings.
The configuration option "verify_email_enabled" will only validate email only on sign up.
Software | From | Fixed in |
---|---|---|
![]() |
2.5.0 | 9.5.16 |
![]() |
10.0.0 | 10.0.11 |
![]() |
10.1.0 | 10.1.7 |
![]() |
10.2.0 | 10.2.4 |
![]() |
10.3.0 | 10.3.3 |
grafana / grafana | 10.1.0 | 10.1.0.x |
grafana / grafana | 10.2.0 | 10.2.0.x |
grafana / grafana | 10.3.0 | 10.3.0.x |
grafana / grafana | 10.0.0 | 10.0.0.x |
grafana / grafana | - | 2.5.0.x |