PT-2024-27674 · Lunary · Lunary
Published
2024-05-20
·
Updated
2025-01-10
·
CVE-2024-3761
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
lunary-ai/lunary versions 1.2.2 through 1.2.7
Description
The issue is related to the DELETE endpoint located at
packages/backend/src/api/v1/datasets, which is vulnerable to unauthorized dataset deletion due to missing authorization and authentication mechanisms. This allows any user, even those without a valid token, to delete a dataset by sending a DELETE request to the endpoint. The impact of this issue is significant as it permits unauthorized users to delete datasets, potentially leading to data loss or disruption of service.Recommendations
For versions 1.2.2 through 1.2.7, update to version 1.2.8 to resolve the issue. As a temporary workaround, consider restricting access to the
packages/backend/src/api/v1/datasets endpoint until the update is applied. Additionally, restricting the use of the DELETE request method on this endpoint can help minimize the risk of exploitation.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lunary