← Retour aux CVEs
CVE-2024-1741
CRITICAL9.1
Description
lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify, and delete prompt templates using an old authorization token. Despite being removed from an organization, these members can still perform operations on prompt templates by sending HTTP requests with their previously captured authorization token. This issue exposes organizations to unauthorized access and manipulation of sensitive template data.
Details CVE
Score CVSS v3.19.1
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie4/10/2024
Derniere modification1/31/2025
Sourcenvd
Observations honeypot0
Produits affectes
lunary:lunary
Faiblesses (CWE)
CWE-863CWE-863
References
https://github.com/lunary-ai/lunary/commit/d8e2e73efd53ab4e92cf47bbf4b639a9f08853d2(security@huntr.dev)
https://huntr.com/bounties/671bd040-1cc5-4227-8182-5904e9c5ed3b(security@huntr.dev)
https://github.com/lunary-ai/lunary/commit/d8e2e73efd53ab4e92cf47bbf4b639a9f08853d2(af854a3a-2127-422b-91ae-364da2661108)
https://huntr.com/bounties/671bd040-1cc5-4227-8182-5904e9c5ed3b(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.