PT-2024-18191 · Git+1 · Lunary+1

Published

2024-04-10

·

Updated

2024-04-10

·

CVE-2024-1643

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue allows an attacker to join an organization without permission by knowing the organization's ID, granting them the ability to read and modify all data within that organization. This poses a significant security risk due to insufficient verification of user permissions when joining an organization.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-1643

Affected Products

Lunary
Lunary-Ai/Lunary