CVE-2024-3379
- EPSS 0.13%
- Veröffentlicht 14.11.2024 18:15:18
- Zuletzt bearbeitet 18.11.2024 21:30:49
In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key for projects they do not have access to. Specifically, a user with a 'Member' role can issue a request...
CVE-2024-7456
- EPSS 23.75%
- Veröffentlicht 01.11.2024 12:15:03
- Zuletzt bearbeitet 06.11.2024 15:45:58
A SQL injection vulnerability exists in the `/api/v1/external-users` route of lunary-ai/lunary version v1.4.2. The `order by` clause of the SQL query uses `sql.unsafe` without prior sanitization, allowing for SQL injection. The `orderByClause` variab...
CVE-2024-7473
- EPSS 0.15%
- Veröffentlicht 29.10.2024 13:15:09
- Zuletzt bearbeitet 03.11.2024 17:15:15
An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability allows an authenticated user to update other users' prompts by manipulating the 'id' parameter in the re...
CVE-2024-7475
- EPSS 0.18%
- Veröffentlicht 29.10.2024 13:15:09
- Zuletzt bearbeitet 15.10.2025 13:15:52
An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to manipulation of authentication processes, fraudulent login requests, ...
CVE-2024-7474
- EPSS 0.16%
- Veröffentlicht 29.10.2024 13:15:09
- Zuletzt bearbeitet 09.01.2025 18:15:29
In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view or delete external users by manipulating the 'id' parameter in the request URL. The application does not perform adequate checks on...
CVE-2024-7472
- EPSS 0.14%
- Veröffentlicht 29.10.2024 13:15:09
- Zuletzt bearbeitet 15.10.2025 13:15:52
lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (/auth/signup). An unauthenticated attacker can inject data into outgoing emails by bypassing the extr...
CVE-2024-6867
- EPSS 0.18%
- Veröffentlicht 13.09.2024 17:15:13
- Zuletzt bearbeitet 19.09.2024 18:28:05
An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endpoint. This endpoint does not verify that the user has the necessary access rights to the run(s) they are accessing. As a result, i...
CVE-2024-6862
- EPSS 0.33%
- Veröffentlicht 13.09.2024 17:15:13
- Zuletzt bearbeitet 19.09.2024 18:37:20
A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive CORS settings. This vulnerability allows an attacker to sign up for and create projects or use the instance as if they were a user wi...
CVE-2024-6582
- EPSS 0.18%
- Veröffentlicht 13.09.2024 17:15:13
- Zuletzt bearbeitet 03.11.2024 17:15:15
A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The `saml.ts` file allows a user from one organization to update the Identity Provider (IDP) settings and view the SSO metadata of another organization. This vuln...
CVE-2024-6087
- EPSS 0.14%
- Veröffentlicht 13.09.2024 17:15:13
- Zuletzt bearbeitet 15.10.2025 13:15:49
An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. The vulnerability allows an attacker to use the auth tokens issued by the 'invite user' functionality to obtain valid JWT tokens. T...