An Improper Access Control vulnerability exists in lunary-ai/lunary version 1.2.2, where users can view and update any prompts in any projects due to insufficient access control checks in the handling of PATCH and GET requests for template versions. This vulnerability allows unauthorized users to manipulate or access sensitive project data, potentially leading to data integrity and confidentiality issues.
References
Link | Resource |
---|---|
https://github.com/lunary-ai/lunary/commit/ddfd497afd017a6946c582a1a806687fdac888bf | |
https://huntr.com/bounties/4acfef85-dedf-43bd-8438-0d8aaa4ffa01 | Exploit Issue Tracking Patch Third Party Advisory |
https://huntr.com/bounties/4acfef85-dedf-43bd-8438-0d8aaa4ffa01 | Exploit Issue Tracking Patch Third Party Advisory |
Configurations
History
31 Jan 2025, 11:15
Type | Values Removed | Values Added |
---|---|---|
CWE | ||
References |
|
10 Jan 2025, 14:38
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
CPE | cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:* | |
CWE | CWE-639 | |
First Time |
Lunary lunary
Lunary |
|
References | () https://huntr.com/bounties/4acfef85-dedf-43bd-8438-0d8aaa4ffa01 - Exploit, Issue Tracking, Patch, Third Party Advisory |
21 Nov 2024, 09:42
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://huntr.com/bounties/4acfef85-dedf-43bd-8438-0d8aaa4ffa01 - |
20 May 2024, 15:17
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-20 15:15
Updated : 2025-01-31 11:15
NVD link : CVE-2024-4151
Mitre link : CVE-2024-4151
CVE.ORG link : CVE-2024-4151
JSON object : View
Products Affected
lunary
- lunary
CWE
CWE-639
Authorization Bypass Through User-Controlled Key