PT-2024-34585 · Lunary · Lunary

Published

2024-06-06

·

Updated

2024-11-03

·

CVE-2024-5128

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions lunary-ai/lunary versions up to and including 1.2.2
Description An Insecure Direct Object Reference (IDOR) vulnerability was identified, allowing unauthorized users to view, update, or delete any dataset prompt or dataset prompt variation within any dataset or project. The issue stems from improper access control checks in the dataset management endpoints, where direct references to object IDs are not adequately secured against unauthorized access.
Recommendations For versions up to and including 1.2.2, upgrade to version 1.2.25 to resolve the issue. As a temporary workaround, consider restricting access to the dataset management endpoints to minimize the risk of exploitation.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-5128

Affected Products

Lunary