7.3
CVE-2024-8765
- EPSS 0.78%
- Veröffentlicht 20.03.2025 10:10:37
- Zuletzt bearbeitet 02.07.2025 19:51:11
- Quelle security@huntr.dev
- CVE-Watchlists
- Unerledigt
Improper Path Equivalence Resolution in lunary-ai/lunary
In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies certain endpoints as public if the path contains '/auth/' anywhere within it. This allows unauthenticated attackers to access sensitive endpoints by including '/auth/' in the path. As a result, attackers can obtain and modify sensitive data and utilize other organizations' resources without proper authentication.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.78% | 0.511 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@huntr.dev | 7.3 | 3.9 | 3.4 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
|
CWE-41 Improper Resolution of Path Equivalence
The product is vulnerable to file system contents disclosure through path equivalence. Path equivalence involves the use of special characters in file and directory names. The associated manipulations are intended to generate multiple names for the same object.
https://github.com/lunary-ai/lunary/commit/7ff89b0304d191534b924cf063f3648206d497fa
https://huntr.com/bounties/4908cfcf-607a-412a-9635-966cbb08bb49