PT-2024-25481 · Lunary · Lunary
Published
2024-11-14
·
Updated
2024-11-18
·
CVE-2024-3379
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
lunary-ai/lunary versions 1.2.2 through 1.2.6
Description
The issue allows unprivileged users to re-generate the private key for projects they do not have access to. Specifically, a user with a 'Member' role can issue a request to regenerate the private key of a project without having the necessary permissions or being assigned to that project.
Recommendations
For versions 1.2.2 through 1.2.6, update to version 1.2.7 to resolve the issue. As a temporary workaround, consider restricting access to project key regeneration functionality to minimize the risk of exploitation.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lunary