CVE-2024-3761
- EPSS 0.17%
- Veröffentlicht 20.05.2024 09:15:09
- Zuletzt bearbeitet 10.01.2025 14:36:20
In lunary-ai/lunary version 1.2.2, the DELETE endpoint located at `packages/backend/src/api/v1/datasets` is vulnerable to unauthorized dataset deletion due to missing authorization and authentication mechanisms. This vulnerability allows any user, ev...
CVE-2024-1739
- EPSS 0.18%
- Veröffentlicht 16.04.2024 00:15:10
- Zuletzt bearbeitet 18.06.2025 16:33:52
lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the server fails to treat email addresses as case insensitive, allowing the creation of multiple accounts...
CVE-2024-1738
- EPSS 0.16%
- Veröffentlicht 16.04.2024 00:15:10
- Zuletzt bearbeitet 10.01.2025 14:35:21
An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.get route in the evaluations API endpoint. This vulnerability allows unauthorized users to retrieve the results of any organizatio...
CVE-2024-1666
- EPSS 0.09%
- Veröffentlicht 16.04.2024 00:15:10
- Zuletzt bearbeitet 10.01.2025 14:34:01
In lunary-ai/lunary version 1.0.0, an authorization flaw exists that allows unauthorized radar creation. The vulnerability stems from the lack of server-side checks to verify if a user is on a free account during the radar creation process, which is ...
CVE-2024-1626
- EPSS 0.1%
- Veröffentlicht 16.04.2024 00:15:09
- Zuletzt bearbeitet 31.01.2025 11:15:10
An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary repository, version 0.3.0, within the project update endpoint. The vulnerability allows authenticated users to modify the name of any project within the system wi...
CVE-2024-1902
- EPSS 0.1%
- Veröffentlicht 10.04.2024 17:15:53
- Zuletzt bearbeitet 10.01.2025 14:29:55
lunary-ai/lunary is vulnerable to a session reuse attack, allowing a removed user to change the organization name without proper authorization. The vulnerability stems from the lack of validation to check if a user is still part of an organization be...
CVE-2024-1741
- EPSS 0.16%
- Veröffentlicht 10.04.2024 17:15:53
- Zuletzt bearbeitet 31.01.2025 11:15:10
lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify, and delete prompt templates using an old authorization token. Despite being removed from an organization, these members can stil...
CVE-2024-1740
- EPSS 0.13%
- Veröffentlicht 10.04.2024 17:15:53
- Zuletzt bearbeitet 10.01.2025 14:21:52
In lunary-ai/lunary version 1.0.1, a vulnerability exists where a user removed from an organization can still read, create, modify, and delete logs by re-using an old authorization token. The lunary web application communicates with the server using ...
CVE-2024-1625
- EPSS 0.1%
- Veröffentlicht 10.04.2024 17:15:52
- Zuletzt bearbeitet 30.01.2025 13:15:09
An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary application version 0.3.0, allowing unauthorized deletion of any organization's project. The vulnerability is due to insufficient authorization checks in the proj...