CVE-2024-5129
- EPSS 0.14%
- Veröffentlicht 06.06.2024 19:16:04
- Zuletzt bearbeitet 21.11.2024 09:47:02
A Privilege Escalation Vulnerability exists in lunary-ai/lunary version 1.2.2, where any user can delete any datasets due to missing authorization checks. The vulnerability is present in the dataset deletion functionality, where the application fails...
CVE-2024-5126
- EPSS 0.12%
- Veröffentlicht 06.06.2024 19:16:04
- Zuletzt bearbeitet 15.10.2025 13:15:45
An improper access control vulnerability exists in the lunary-ai/lunary repository, specifically within the versions.patch functionality for updating prompts. Affected versions include 1.2.2 up to but not including 1.2.25. The vulnerability allows un...
CVE-2024-5128
- EPSS 0.19%
- Veröffentlicht 06.06.2024 19:16:04
- Zuletzt bearbeitet 21.11.2024 09:47:01
An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to and including 1.2.2. This vulnerability allows unauthorized users to view, update, or delete any dataset_prompt or dataset_prompt_va...
CVE-2024-5130
- EPSS 0.3%
- Veröffentlicht 06.06.2024 19:16:04
- Zuletzt bearbeitet 15.10.2025 13:15:45
An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete any dataset. The vulnerability is due to the lack of proper authorization checks in the dataset delet...
CVE-2024-5277
- EPSS 0.14%
- Veröffentlicht 06.06.2024 18:15:20
- Zuletzt bearbeitet 21.11.2024 09:47:20
In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password token is not invalidated after use. This allows an attacker who compromises the recovery token to repeatedly change the password of ...
CVE-2024-5127
- EPSS 0.1%
- Veröffentlicht 06.06.2024 18:15:19
- Zuletzt bearbeitet 21.11.2024 09:47:01
In lunary-ai/lunary versions 1.2.2 through 1.2.25, an improper access control vulnerability allows users on the Free plan to invite other members and assign them any role, including those intended for Paid and Enterprise plans only. This issue arises...
CVE-2024-3504
- EPSS 0.14%
- Veröffentlicht 06.06.2024 18:15:17
- Zuletzt bearbeitet 15.10.2025 13:15:43
An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization user to the organization owner. This vulnerability allows the elevated user to delete projects within t...
CVE-2024-4148
- EPSS 0.17%
- Veröffentlicht 01.06.2024 16:15:07
- Zuletzt bearbeitet 30.01.2025 13:15:10
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary application, version 1.2.10. An attacker can exploit this vulnerability by maliciously manipulating regular expressions, which can significantly impact the re...
CVE-2024-4154
- EPSS 0.11%
- Veröffentlicht 21.05.2024 18:15:09
- Zuletzt bearbeitet 31.01.2025 11:15:10
In lunary-ai/lunary version 1.2.2, an incorrect synchronization vulnerability allows unprivileged users to rename projects they do not have access to. Specifically, an unprivileged user can send a PATCH request to the project's endpoint with a new na...
CVE-2024-4151
- EPSS 0.13%
- Veröffentlicht 20.05.2024 15:15:08
- Zuletzt bearbeitet 31.01.2025 11:15:10
An Improper Access Control vulnerability exists in lunary-ai/lunary version 1.2.2, where users can view and update any prompts in any projects due to insufficient access control checks in the handling of PATCH and GET requests for template versions. ...