Server-Side Request Forgery Vulnerability in Lunary Application
CVE-2024-5328

9.3CRITICAL

Key Information:

Vendor
Lunary-ai
Status
Lunary-ai/lunary
Vendor
CVE Published:
6 June 2024

Summary

A Server-Side Request Forgery (SSRF) vulnerability exists in Lunary AI's Lunary application, specifically at the endpoint '/auth/saml/tto/download-idp-xml'. This vulnerability is due to inadequate validation of user-supplied URLs before executing server-side requests. An attacker can exploit this flaw by crafting a malicious request targeting the vulnerable endpoint, facilitating unauthorized access to both internal and external resources. The potential impacts include the disclosure of sensitive information, service interruptions, and possible exacerbation of network infrastructure attacks. This concern affects all users of the latest version of the Lunary application.

Affected Version(s)

lunary-ai/lunary <= unspecified

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.