PT-2025-12033 · Lunary · Lunary

CVE-2024-10272

·

Published

2025-03-20

·

Updated

2025-06-20

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions lunary-ai/lunary version latest
Description The issue allows an attacker to view the content of any dataset without authorization by sending a GET request to the "/v1/datasets" endpoint without a valid authorization token.
Recommendations For the latest version, consider restricting access to the "/v1/datasets" endpoint until a patch is available. As a temporary workaround, ensure that all requests to this endpoint include a valid authorization token to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10272

Affected Products

Lunary