lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify, and delete prompt templates using an old authorization token. Despite being removed from an organization, these members can still perform operations on prompt templates by sending HTTP requests with their previously captured authorization token. This issue exposes organizations to unauthorized access and manipulation of sensitive template data.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2024-04-10T17:08:04.411Z

Updated: 2024-08-11T14:19:25.731Z

Reserved: 2024-02-22T11:55:00.476Z

Link: CVE-2024-1741

cve-icon Vulnrichment

Updated: 2024-08-01T18:48:22.013Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-10T17:15:53.483

Modified: 2024-04-15T18:15:09.937

Link: CVE-2024-1741

cve-icon Redhat

No data.