An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endpoint. This endpoint does not verify that the user has the necessary access rights to the run(s) they are accessing. As a result, it returns not only the specified run but also all runs that have the `run_id` listed as their parent run. This issue affects the main branch, commit a761d833. The vulnerability allows unauthorized users to obtain information about non-public runs and their related runs, given the `run_id` of a public or non-public run.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Sep 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lunary
Lunary lunary |
|
CPEs | cpe:2.3:a:lunary:lunary:1.4.9:*:*:*:*:*:*:* | |
Vendors & Products |
Lunary
Lunary lunary |
|
Metrics |
cvssV3_1
|
Fri, 13 Sep 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lunary-ai
Lunary-ai lunary-ai\/lunary |
|
CPEs | cpe:2.3:a:lunary-ai:lunary-ai\/lunary:*:*:*:*:*:*:*:* | |
Vendors & Products |
Lunary-ai
Lunary-ai lunary-ai\/lunary |
|
Metrics |
ssvc
|
Fri, 13 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endpoint. This endpoint does not verify that the user has the necessary access rights to the run(s) they are accessing. As a result, it returns not only the specified run but also all runs that have the `run_id` listed as their parent run. This issue affects the main branch, commit a761d833. The vulnerability allows unauthorized users to obtain information about non-public runs and their related runs, given the `run_id` of a public or non-public run. | |
Title | Information Disclosure in lunary-ai/lunary | |
Weaknesses | CWE-1220 | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-09-13T16:13:02.869Z
Updated: 2024-09-13T16:38:51.331Z
Reserved: 2024-07-17T21:16:51.698Z
Link: CVE-2024-6867
Vulnrichment
Updated: 2024-09-13T16:38:44.228Z
NVD
Status : Analyzed
Published: 2024-09-13T17:15:13.613
Modified: 2024-09-19T18:28:05.477
Link: CVE-2024-6867
Redhat
No data.