{"id":"CVE-2024-10452","aliases":["GHSA-66c4-2g2v-54qw","BIT-grafana-2024-10452","GO-2024-3240"],"title":"Grafana org admin can delete pending invites in different org","summary":"Grafana org admin can delete pending invites in different org","severity":"low","cvss":2.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N","vendor":"grafana","product":"github.com/grafana/grafana","ecosystem":"go","affected":["github.com/grafana/grafana <= 10.4.0"],"published":"2024-10-29","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:19.290379294Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-66c4-2g2v-54qw","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-10452"},{"url":"https://github.com/advisories/GHSA-66c4-2g2v-54qw"},{"url":"https://github.com/grafana/grafana"},{"url":"https://grafana.com/security/security-advisories/cve-2024-10452"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-10452"}],"tags":["osv","go"],"epss":0.00486,"epssPercentile":0.40926,"ingestedAt":"2026-09-12T03:13:01.757Z","slug":"CVE-2024-10452","body":"## Overview\n\nOrganization admins can delete pending invites created in an organization they are not part of.\n\n## Affected packages\n\n- `github.com/grafana/grafana <= 10.4.0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":12,"depthScoreParts":{"impact":12.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}