PT-2024-29428 · Lunary Ai · Lunary
Published
2024-05-20
·
Updated
2025-01-31
·
CVE-2024-4151
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
lunary-ai/lunary version 1.2.2
Description
The issue is related to insufficient access control checks in the handling of
PATCH and GET requests for template versions, allowing unauthorized users to view and update any prompts in any projects. This can lead to data integrity and confidentiality issues.Recommendations
For version 1.2.2, upgrade to a patched version as soon as possible to prevent unauthorized access. As a temporary workaround, consider restricting access to the
PATCH and GET requests for template versions until a patch is available.Exploit
Fix
Improper Access Control
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lunary