Server-Side Request Forgery Vulnerability in Lunary Application
CVE-2024-5328
9.3CRITICAL
What is CVE-2024-5328?
A Server-Side Request Forgery (SSRF) vulnerability exists in Lunary AI's Lunary application, specifically at the endpoint '/auth/saml/tto/download-idp-xml'. This vulnerability is due to inadequate validation of user-supplied URLs before executing server-side requests. An attacker can exploit this flaw by crafting a malicious request targeting the vulnerable endpoint, facilitating unauthorized access to both internal and external resources. The potential impacts include the disclosure of sensitive information, service interruptions, and possible exacerbation of network infrastructure attacks. This concern affects all users of the latest version of the Lunary application.
Affected Version(s)
lunary-ai/lunary <= unspecified