PT-2024-34590 · Lunary Ai · Lunary

Published

2024-06-06

·

Updated

2025-10-15

·

CVE-2024-5130

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions lunary-ai/lunary versions up to and including 1.2.2
Description An Incorrect Authorization issue exists, allowing unauthenticated users to delete any dataset due to the lack of proper authorization checks in the dataset deletion endpoint. The endpoint does not verify if the provided project ID belongs to the current user, thereby allowing any dataset to be deleted without proper authentication.
Recommendations For versions up to and including 1.2.2, update to version 1.2.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the dataset deletion endpoint until a patch is available.

Exploit

Fix

IDOR

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-5130

Affected Products

Lunary