CVE-2024-10452
Aliases:GHSA-66c4-2g2v-54qwBIT-grafana-2024-10452GO-2024-3240CGA-22g3-p622-cpccCGA-3r3j-cfvr-gw3qCGA-4f3q-285q-7rrmCGA-4hpj-w242-7wg5CGA-4m7p-vrrj-vx5pCGA-59gr-3cc8-2h4cCGA-59qp-f6q9-m86fCGA-64pc-rgxc-jgj4CGA-6xr9-j3p4-pch7CGA-7xxh-mvxg-qq4cCGA-822r-j89f-gpw9CGA-83c9-2gqg-5wwrCGA-88hv-9rm8-3wxmCGA-96vc-83rm-p7pgCGA-9f89-96vg-gh28CGA-cw3q-jq27-m9mmCGA-f6jv-frp2-596xCGA-fg8r-pp73-hj98CGA-fw3p-xcff-336vCGA-g4xf-7325-553vCGA-jf8v-jjc6-jrqqCGA-m36j-54rx-vgf3CGA-mxx9-6876-2437CGA-pghf-hv2j-3fpcCGA-pj3v-j25f-pwfmCGA-pqh9-4x7q-xwm4CGA-qp84-vfhp-g3jcCGA-qx6q-84j5-37mxCGA-rg2q-72mm-3vqxCGA-rm2h-363h-9rv8CGA-rq8m-c555-8jwfCGA-rqx6-552h-c2qjCGA-vq37-hrpv-646fCGA-vv6p-5rjm-68hjCGA-w8rw-hf8x-v7vwCGA-wfw4-9m5g-w6h8CGA-wgcp-xqvc-fc9vCGA-wpq2-wv5r-fr53CGA-x8w4-3jx8-349qCGA-xr4j-8mx9-rcm7
Advisory lineage Upstream: 0 Downstream: 4
Analyzed
Published: 29 Oct 2024, 15:16
Last modified:29 Oct 2024, 15:35
Vulnerability Summary
Overall Risk (default)
low
11/100 CVSS Score
2.7 LOW
v3.1 (nvd)
EPSS Score
0.49% LOW
0% probability +0.28%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
29 Oct 2024, 15:16
Published
Vulnerability first disclosed
29 Oct 2024, 15:35
Last Modified
Vulnerability information updated
Description
Organization admins can delete pending invites created in an organization they are not part of.
CVSS Metrics
- v4.0•LOW•Score: 2.1CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- v3.1•LOW•Score: 2.2CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
- v3.1•LOW•Score: 2.7CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
EPSS Trends
Current EPSS score: 0.49%• Percentile: 41%
Techniques & Countermeasures
- CWE-639•Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Affected Systems
- chainguard•grafana-fips-11.6
< 0
- chainguard•grafana-fips-12.0
< 12.0.10-r6
- chainguard•grafana-fips-12.1
< 12.1.10.01-r3
- chainguard•grafana-fips-12.2
< 12.2.10-r0
- chainguard•grafana-fips-12.3
< 0
- chainguard•grafana-fips-12.4
< 0
- chainguard•grafana-fips-13.0
< 0
- chainguard•grafana-fips-13.1
< 0
- github.com/grafana•grafana
all | ≤ 10.4.0
- grafana•grafana
10.4.0
References (6)
- https://grafana.com/security/security-advisories/cve-2024-10452
- https://nvd.nist.gov/vuln/detail/CVE-2024-10452
- https://github.com/advisories/GHSA-66c4-2g2v-54qw
- https://github.com/grafana/grafana
- https://www.cve.org/CVERecord?id=CVE-2024-10452
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/10xxx/CVE-2024-10452.json