← Retour aux CVEs
CVE-2024-1739
CRITICAL9.1
Description
lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the server fails to treat email addresses as case insensitive, allowing the creation of multiple accounts with the same email address by varying the case of the email characters. For example, accounts for 'abc@gmail.com' and 'Abc@gmail.com' can both be created, leading to potential impersonation and confusion among users.
Details CVE
Score CVSS v3.19.1
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie4/16/2024
Derniere modification6/18/2025
Sourcenvd
Observations honeypot0
Produits affectes
lunary:lunary
Faiblesses (CWE)
CWE-821
References
https://github.com/lunary-ai/lunary/commit/7351157a21e5acd0162b4528bcae9d65b1c95695(security@huntr.dev)
https://huntr.com/bounties/2ca70ba5-b6a4-4873-bd55-bc6cef40d300(security@huntr.dev)
https://github.com/lunary-ai/lunary/commit/7351157a21e5acd0162b4528bcae9d65b1c95695(af854a3a-2127-422b-91ae-364da2661108)
https://huntr.com/bounties/2ca70ba5-b6a4-4873-bd55-bc6cef40d300(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.