CVE-2024-10452
Low
CVE-2024-10452
Organization admins can delete pending invites created in an organization they are not part of.
Exploit probability
0.5%
Published
October 31, 2024
Required by
Not available
Last source change
February 11, 2026
02 / AFFECTED SOFTWARE
Affected packages
2 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
BIT-grafana-2024-10452
View original source
Organization admins can delete pending invites created in an organization they are not part of.
Open Source Vulnerabilities
GO-2024-3240
View original source
Grafana org admin can delete pending invites in different org in github.com/grafana/grafana
Open Source Vulnerabilities
GHSA-66c4-2g2v-54qw
View original source
Organization admins can delete pending invites created in an organization they are not part of.
Open Source Vulnerabilities
CVE-2024-10452
View original source
Organization admins can delete pending invites created in an organization they are not part of.
05 / REFERENCES
Further evidence
- https://github.com/grafana/grafana/pull/95476
- https://github.com/grafana/grafana/pull/95486
- https://github.com/grafana/grafana/pull/95487
- https://github.com/grafana/grafana/pull/95488
- https://github.com/grafana/grafana/pull/95489
- https://github.com/grafana/grafana/pull/95490
- https://grafana.com/security/security-advisories/cve-2024-10452
- https://nvd.nist.gov/vuln/detail/CVE-2024-10452
- https://github.com/advisories/GHSA-66c4-2g2v-54qw
- https://www.cve.org/CVERecord?id=CVE-2024-10452
- https://github.com/grafana/grafana
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/10xxx/CVE-2024-10452.json