PT-2024-37376 · Lunary Ai · Lunary

Published

2024-06-27

·

Updated

2024-09-19

·

CVE-2024-6086

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: lunary-ai/lunary version 1.2.7
Description: The issue allows any authenticated user to change the name of an organization due to improper access control. This is because the checkAccess() function is not implemented, enabling users with low privileges, such as the Prompt Editor role, to modify organization attributes without proper authorization.
Recommendations: For version 1.2.7, consider disabling the checkAccess() function temporarily, or restrict the modification of organization attributes to only authorized users until a proper fix is implemented. Additionally, review and implement proper access control mechanisms to prevent unauthorized modifications.

Exploit

Fix

Improper Access Control

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-6086

Affected Products

Lunary