Cross-Site Request Forgery (CSRF) Vulnerability in Lunary Version 1.2.34
CVE-2024-6862
8.1HIGH
Key Information:
- Vendor
- Lunary-ai
- Status
- Lunary-ai/lunary
- Vendor
- CVE Published:
- 13 September 2024
Summary
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Lunary AI's Lunary product, specifically in version 1.2.34. The flaw arises from overly permissive CORS settings that allow for all origins, thus exposing unauthenticated endpoints. Attackers can exploit this vulnerability to impersonate legitimate users, create projects, and perform tasks as if they had local access. This issue predominantly affects instances running locally on personal machines that are not publicly accessible. The existing CORS configuration does not adequately restrict access, which poses significant security risks.
Affected Version(s)
lunary-ai/lunary < 1.4.10
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database