An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization user to the organization owner. This vulnerability allows the elevated user to delete projects within the organization. The issue is resolved in version 1.2.7.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Oct 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lunary
Lunary lunary |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:* | |
Vendors & Products |
Lunary
Lunary lunary |
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-06-06T17:53:40.589Z
Updated: 2024-08-01T20:12:07.852Z
Reserved: 2024-04-09T02:08:37.707Z
Link: CVE-2024-3504
Vulnrichment
Updated: 2024-08-01T20:12:07.852Z
NVD
Status : Modified
Published: 2024-06-06T18:15:17.980
Modified: 2024-11-21T09:29:44.783
Link: CVE-2024-3504
Redhat
No data.