PT-2024-37376 · Lunary Ai · Lunary
Published
2024-06-27
·
Updated
2024-09-19
·
CVE-2024-6086
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
lunary-ai/lunary version 1.2.7
Description:
The issue allows any authenticated user to change the name of an organization due to improper access control. This is because the
checkAccess() function is not implemented, enabling users with low privileges, such as the Prompt Editor role, to modify organization attributes without proper authorization.Recommendations:
For version 1.2.7, consider disabling the
checkAccess() function temporarily, or restrict the modification of organization attributes to only authorized users until a proper fix is implemented. Additionally, review and implement proper access control mechanisms to prevent unauthorized modifications.Exploit
Fix
Improper Access Control
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lunary