Cross-Site Request Forgery (CSRF) Vulnerability in Lunary Version 1.2.34
CVE-2024-6862
8.1HIGH
Key Information
- Vendor
- Lunary-ai
- Status
- Lunary-ai/lunary
- Vendor
- CVE Published:
- 13 September 2024
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive CORS settings. This vulnerability allows an attacker to sign up for and create projects or use the instance as if they were a user with local access. The main attack vector is for instances hosted locally on personal machines, which are not publicly accessible. The CORS settings in the backend permit all origins, exposing unauthenticated endpoints to CSRF attacks.
Affected Version(s)
lunary-ai/lunary < 1.4.10
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Risk change from: null to: 7.4 - (HIGH)
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database