Access Control Flaw in Lunary AI Before Version 1.5.9
CVE-2024-10762
8.1HIGH
What is CVE-2024-10762?
The Lunary AI platform, prior to version 1.5.9, contains a significant access control vulnerability in the /v1/evaluators/ endpoint. This issue permits users with insufficient privileges to execute DELETE requests, thereby enabling them to remove evaluators from a project without appropriate authorization. The absence of adequate middleware to verify user roles allows this exploitation, leading to potential permanent data loss and disruptions in project operations. It is essential for users and administrators to ensure they upgrade to the latest version to mitigate this risk.
Affected Version(s)
lunary-ai/lunary < 1.5.9