{"id":"BIT-grafana-2020-27846","details":"A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.","aliases":["CVE-2020-27846","GHSA-4hq8-gmxx-h6w9","GO-2021-0058"],"modified":"2026-09-08T08:47:36.146571586Z","published":"2024-03-06T11:00:29.021Z","database_specific":{"severity":"Critical","cpes":["cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*"]},"references":[{"type":"ADVISORY","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1907670"},{"type":"ADVISORY","url":"https://github.com/crewjam/saml/security/advisories/GHSA-4hq8-gmxx-h6w9"},{"type":"ADVISORY","url":"https://grafana.com/blog/2020/12/17/grafana-6.7.5-7.2.3-and-7.3.6-released-with-important-security-fix-for-grafana-enterprise/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YUTKIRWT6TWU7DS6GF3EOANVQBFQZYI/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ICP3YRY2VUCNCF2VFUSK77ZMRIC77FEM/"},{"type":"ADVISORY","url":"https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20210205-0002/"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-27846"}],"affected":[{"package":{"name":"grafana","ecosystem":"Bitnami","purl":"pkg:bitnami/grafana"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.7.5"},{"introduced":"7.0.0"},{"fixed":"7.2.3"},{"introduced":"7.3.0"},{"fixed":"7.3.6"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2020-27846.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}],"schema_version":"1.9.0"}