CVE-2024-7476

A broken access control vulnerability exists in lunary-ai/lunary versions 1.2.7 through 1.4.2. The vulnerability allows an authenticated attacker to modify any user's templates by sending a crafted HTTP POST request to the /v1/templates/{id}/versions endpoint. This issue is resolved in version 1.4.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:*

History

02 Jul 2025, 19:49

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de control de acceso erróneo en las versiones 1.2.7 a 1.4.2 de lunary-ai/lunary. Esta vulnerabilidad permite a un atacante autenticado modificar las plantillas de cualquier usuario mediante el envío de una solicitud HTTP POST manipulada al endpoint /v1/templates/{id}/versions. Este problema se ha resuelto en la versión 1.4.3.
References () https://github.com/lunary-ai/lunary/commit/8f563c77d8614a72980113f530c7a9ec15a5f8d5 - () https://github.com/lunary-ai/lunary/commit/8f563c77d8614a72980113f530c7a9ec15a5f8d5 - Patch
References () https://huntr.com/bounties/183761f7-d411-4332-af86-2ccfbcc5bd9f - () https://huntr.com/bounties/183761f7-d411-4332-af86-2ccfbcc5bd9f - Exploit, Third Party Advisory
CPE cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:*
First Time Lunary
Lunary lunary

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-02 19:49


NVD link : CVE-2024-7476

Mitre link : CVE-2024-7476

CVE.ORG link : CVE-2024-7476


JSON object : View

Products Affected

lunary

  • lunary
CWE
CWE-284

Improper Access Control