In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key for projects they do not have access to. Specifically, a user with a 'Member' role can issue a request to regenerate the private key of a project without having the necessary permissions or being assigned to that project. This issue was fixed in version 1.2.7.
Metrics
Affected Vendors & Products
References
History
Mon, 18 Nov 2024 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lunary
Lunary lunary |
|
CPEs | cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:* | |
Vendors & Products |
Lunary
Lunary lunary |
Mon, 18 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lunary-ai
Lunary-ai lunary-ai\/lunary |
|
CPEs | cpe:2.3:a:lunary-ai:lunary-ai\/lunary:*:*:*:*:*:*:*:* | |
Vendors & Products |
Lunary-ai
Lunary-ai lunary-ai\/lunary |
|
Metrics |
cvssV3_1
|
Thu, 14 Nov 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key for projects they do not have access to. Specifically, a user with a 'Member' role can issue a request to regenerate the private key of a project without having the necessary permissions or being assigned to that project. This issue was fixed in version 1.2.7. | |
Title | Incorrect Authorization in lunary-ai/lunary | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-11-14T17:34:26.930Z
Updated: 2024-11-18T15:54:25.147Z
Reserved: 2024-04-05T15:31:18.306Z
Link: CVE-2024-3379
Vulnrichment
Updated: 2024-11-18T15:53:49.116Z
NVD
Status : Analyzed
Published: 2024-11-14T18:15:18.503
Modified: 2024-11-18T21:30:49.947
Link: CVE-2024-3379
Redhat
No data.