PT-2024-34590 · Lunary Ai · Lunary
Published
2024-06-06
·
Updated
2025-10-15
·
CVE-2024-5130
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
lunary-ai/lunary versions up to and including 1.2.2
Description
An Incorrect Authorization issue exists, allowing unauthenticated users to delete any dataset due to the lack of proper authorization checks in the dataset deletion endpoint. The endpoint does not verify if the provided
project ID belongs to the current user, thereby allowing any dataset to be deleted without proper authentication.Recommendations
For versions up to and including 1.2.2, update to version 1.2.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the dataset deletion endpoint until a patch is available.
Exploit
Fix
IDOR
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lunary