Improper Authorization Vulnerability in Lunary AI by Lunary Technologies
CVE-2024-10274

6.5MEDIUM

Key Information:

Vendor

Lunary-ai

Vendor
CVE Published:
20 March 2025

What is CVE-2024-10274?

An improper authorization vulnerability has been identified in Lunary AI, specifically in version 1.5.5. The affected /users/me/org endpoint fails to implement proper access control measures, enabling unauthorized users to gain access to sensitive information regarding all team members within the organization. This can include the disclosure of personal data such as names, roles, and emails of users who do not possess adequate privileges. The potential repercussions of this vulnerability include severe privacy infringements and the facilitation of reconnaissance efforts for targeted malicious attacks.

Affected Version(s)

lunary-ai/lunary < 1.5.7

References

CVSS V3.0

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.