PT-2024-9679 · Lunary · Lunary

Published

2024-10-29

·

Updated

2025-01-09

·

CVE-2024-7474

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions lunary-ai/lunary version 1.3.2
Description The issue is related to an Insecure Direct Object Reference (IDOR) vulnerability, which allows unauthorized access to external user data by manipulating the id parameter in the request URL. This can enable a remote attacker to impact the integrity and confidentiality of protected information. The application fails to perform adequate checks on the id parameter, allowing users to view or delete external users.
Recommendations For version 1.3.2, consider restricting access to the id parameter in the request URL to prevent unauthorized access to external user data. As a temporary workaround, restrict the ability to manipulate the id parameter until a patch is available. Additionally, ensure that adequate checks are performed on the id parameter to prevent IDOR vulnerabilities.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

BDU:2024-11391
CVE-2024-7474

Affected Products

Lunary