IDOR Vulnerability in lunary-ai/lunary
CVE-2024-5128

8.8HIGH

Key Information:

Vendor

Lunary-ai

Vendor
CVE Published:
6 June 2024

What is CVE-2024-5128?

An Insecure Direct Object Reference (IDOR) vulnerability has been identified in Lunary AI, specifically impacting versions up to and including 1.2.2. This flaw enables unauthorized users to potentially view, update, or delete any dataset prompts or variations associated with datasets or projects. The underlying cause is attributed to inadequate access control checks in the endpoint management for datasets. Direct references to object IDs are insufficiently secured, allowing users to gain unauthorized access. The vulnerability has been addressed in version 1.2.25, reinforcing security protocols for managing dataset access.

Affected Version(s)

lunary-ai/lunary < 1.2.25

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.