PT-2024-34594 · Lunary Ai · Lunary

Published

2024-06-06

·

Updated

2024-06-07

·

CVE-2024-5132

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions lunary-ai/lunary version 1.2.2
Description A business logic error in lunary-ai/lunary allows users to bypass the intended limitations on team member invitations and additions, regardless of their subscription plan. This is due to the lack of validation of SEAT ALLOWANCE constants during invitation processes.
Recommendations For lunary-ai/lunary version 1.2.2, consider restricting the use of team member invitation features until a patch is available to prevent exploitation of the business logic error. Additionally, review and validate the SEAT ALLOWANCE constants to ensure proper enforcement of team member limits according to subscription plans. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2024-5132

Affected Products

Lunary