An Improper Access Control vulnerability exists in lunary-ai/lunary version 1.2.2, where users can view and update any prompts in any projects due to insufficient access control checks in the handling of PATCH and GET requests for template versions. This vulnerability allows unauthorized users to manipulate or access sensitive project data, potentially leading to data integrity and confidentiality issues.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Jan 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lunary
Lunary lunary |
|
Weaknesses | CWE-639 | |
CPEs | cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:* | |
Vendors & Products |
Lunary
Lunary lunary |
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-05-20T14:14:53.399Z
Updated: 2024-08-01T20:33:52.432Z
Reserved: 2024-04-24T21:48:24.330Z
Link: CVE-2024-4151
Vulnrichment
Updated: 2024-08-01T20:33:52.432Z
NVD
Status : Analyzed
Published: 2024-05-20T15:15:08.510
Modified: 2025-01-10T14:38:14.560
Link: CVE-2024-4151
Redhat
No data.