Information Disclosure Vulnerability in Lunary AI Product by Lunary
CVE-2024-3501

8.1HIGH

Key Information:

Vendor

Lunary-ai

Vendor
CVE Published:
14 November 2024

What is CVE-2024-3501?

An information disclosure vulnerability in Lunary AI's product affects versions up to and including 1.2.5, where single-use tokens are inadvertently included in the responses of critical API endpoints such as GET /v1/users/me and GET /v1/users/me/org. These tokens, which should only be accessible for sensitive operations like password resets or account verification, can be exposed to unauthorized users. As a result, attackers may exploit this vulnerability to execute actions that could compromise user accounts. The issue was remedied in version 1.2.6, which mitigated the exposure of these tokens in user-facing responses.

Affected Version(s)

lunary-ai/lunary < 1.2.6

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.