PT-2024-34594 · Lunary Ai · Lunary
Published
2024-06-06
·
Updated
2024-06-07
·
CVE-2024-5132
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
lunary-ai/lunary version 1.2.2
Description
A business logic error in lunary-ai/lunary allows users to bypass the intended limitations on team member invitations and additions, regardless of their subscription plan. This is due to the lack of validation of SEAT ALLOWANCE constants during invitation processes.
Recommendations
For lunary-ai/lunary version 1.2.2, consider restricting the use of team member invitation features until a patch is available to prevent exploitation of the business logic error. Additionally, review and validate the SEAT ALLOWANCE constants to ensure proper enforcement of team member limits according to subscription plans. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lunary