Server-Side Request Forgery Vulnerability in Lunary Application
CVE-2024-5328
Key Information:
- Vendor
- Lunary-ai
- Status
- Lunary-ai/lunary
- Vendor
- CVE Published:
- 6 June 2024
Summary
A Server-Side Request Forgery (SSRF) vulnerability exists in Lunary AI's Lunary application, specifically at the endpoint '/auth/saml/tto/download-idp-xml'. This vulnerability is due to inadequate validation of user-supplied URLs before executing server-side requests. An attacker can exploit this flaw by crafting a malicious request targeting the vulnerable endpoint, facilitating unauthorized access to both internal and external resources. The potential impacts include the disclosure of sensitive information, service interruptions, and possible exacerbation of network infrastructure attacks. This concern affects all users of the latest version of the Lunary application.
Affected Version(s)
lunary-ai/lunary <= unspecified
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved