First published: Tue Oct 29 2024(Updated: )
Organization admins can delete pending invites created in an organization they are not part of.
Credit: security@grafana.com security@grafana.com
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/grafana/grafana | <=10.4.0 | |
Grafana Labs Grafana OSS and Enterprise | =10.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10452 is considered a moderate severity vulnerability affecting Grafana versions up to 10.4.0.
To fix CVE-2024-10452, upgrade Grafana to a version higher than 10.4.0.
CVE-2024-10452 affects organization admins using Grafana version 10.4.0 and below.
An attacker can delete pending invites in organizations they are not a part of due to insufficient access controls.
CVE-2024-10452 is considered a local vulnerability, requiring access to organization administrative features.