PT-2024-37122 · Lunary Ai · Lunary

Published

2024-06-27

·

Updated

2024-09-19

·

CVE-2024-5755

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: lunary-ai/lunary versions <=v1.2.11
Description: The issue allows an attacker to bypass email validation by using a dot character ('.') in the email address, enabling the creation of multiple accounts with essentially the same email address. This can lead to incorrect synchronization and potential security issues.
Recommendations: For versions <=v1.2.11, update to a version greater than v1.2.11 to prevent email validation bypass. As a temporary workaround, consider restricting the use of dot characters in email addresses to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-5755

Affected Products

Lunary