CVE-2024-10452: Low severity grafana labs grafana oss and enterprise vulnerability
Published Oct 29, 2024
·Updated
Organization admins can delete pending invites created in an organization they are not part of.
Affected Software
2 affected components
go/github.com/grafana/grafana<=10.4.0
Grafana Grafana=10.4.0
Event History
Oct 29, 2024
CVE Published
via MITRE·03:16 PM
Data Sourced
via MITRE·03:16 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-10452?
CVE-2024-10452 is considered a moderate severity vulnerability affecting Grafana versions up to 10.4.0.
2
How do I fix CVE-2024-10452?
To fix CVE-2024-10452, upgrade Grafana to a version higher than 10.4.0.
3
Who is affected by CVE-2024-10452?
CVE-2024-10452 affects organization admins using Grafana version 10.4.0 and below.
4
What can an attacker do with CVE-2024-10452?
An attacker can delete pending invites in organizations they are not a part of due to insufficient access controls.
5
Is CVE-2024-10452 a remote or local vulnerability?
CVE-2024-10452 is considered a local vulnerability, requiring access to organization administrative features.