lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify, and delete prompt templates using an old authorization token. Despite being removed from an organization, these members can still perform operations on prompt templates by sending HTTP requests with their previously captured authorization token. This issue exposes organizations to unauthorized access and manipulation of sensitive template data.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-04-10T17:08:04.411Z
Updated: 2024-08-11T14:19:25.731Z
Reserved: 2024-02-22T11:55:00.476Z
Link: CVE-2024-1741
Vulnrichment
Updated: 2024-08-01T18:48:22.013Z
NVD
Status : Awaiting Analysis
Published: 2024-04-10T17:15:53.483
Modified: 2024-04-15T18:15:09.937
Link: CVE-2024-1741
Redhat
No data.