PT-2024-34585 · Lunary · Lunary
Published
2024-06-06
·
Updated
2024-11-03
·
CVE-2024-5128
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
lunary-ai/lunary versions up to and including 1.2.2
Description
An Insecure Direct Object Reference (IDOR) vulnerability was identified, allowing unauthorized users to view, update, or delete any
dataset prompt or dataset prompt variation within any dataset or project. The issue stems from improper access control checks in the dataset management endpoints, where direct references to object IDs are not adequately secured against unauthorized access.Recommendations
For versions up to and including 1.2.2, upgrade to version 1.2.25 to resolve the issue. As a temporary workaround, consider restricting access to the dataset management endpoints to minimize the risk of exploitation.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lunary