Cross-Site Request Forgery (CSRF) Vulnerability in Lunary Version 1.2.34
CVE-2024-6862

8.1HIGH

Key Information:

Vendor
Lunary-ai
Status
Lunary-ai/lunary
Vendor
CVE Published:
13 September 2024

Summary

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Lunary AI's Lunary product, specifically in version 1.2.34. The flaw arises from overly permissive CORS settings that allow for all origins, thus exposing unauthenticated endpoints. Attackers can exploit this vulnerability to impersonate legitimate users, create projects, and perform tasks as if they had local access. This issue predominantly affects instances running locally on personal machines that are not publicly accessible. The existing CORS configuration does not adequately restrict access, which poses significant security risks.

Affected Version(s)

lunary-ai/lunary < 1.4.10

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.