← Zuruck zu CVEs
CVE-2024-1625
MEDIUM6.5
Beschreibung
An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary application version 0.3.0, allowing unauthorized deletion of any organization's project. The vulnerability is due to insufficient authorization checks in the project deletion endpoint, where the endpoint fails to verify if the project ID provided in the request belongs to the requesting user's organization. As a result, an attacker can delete projects belonging to any organization by sending a crafted DELETE request with the target project's ID. This issue affects the project deletion functionality implemented in the projects.delete route.
CVE Details
CVSS v3.1 Bewertung6.5
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht4/10/2024
Zuletzt geandert1/30/2025
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
lunary:lunary
Schwachen (CWE)
CWE-639CWE-639
Referenzen
https://github.com/lunary-ai/lunary/commit/88f98e29f19da9d1f5de45c5b163fd5b48e0bcec(security@huntr.dev)
https://huntr.com/bounties/cf6dd625-e6c9-44df-a072-13686816de21(security@huntr.dev)
https://github.com/lunary-ai/lunary/commit/88f98e29f19da9d1f5de45c5b163fd5b48e0bcec(af854a3a-2127-422b-91ae-364da2661108)
https://huntr.com/bounties/cf6dd625-e6c9-44df-a072-13686816de21(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.