CVE-2024-3504

An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization user to the organization owner. This vulnerability allows the elevated user to delete projects within the organization. The issue is resolved in version 1.2.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:*

History

09 Oct 2024, 15:27

Type Values Removed Values Added
CPE cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Lunary lunary
Lunary
CWE NVD-CWE-noinfo
References () https://github.com/lunary-ai/lunary/commit/f7507f0949f6634f725ebb8da37c44f76542901f - () https://github.com/lunary-ai/lunary/commit/f7507f0949f6634f725ebb8da37c44f76542901f - Patch
References () https://huntr.com/bounties/97958fe4-be21-4b63-966f-8337c72c8e28 - () https://huntr.com/bounties/97958fe4-be21-4b63-966f-8337c72c8e28 - Exploit, Third Party Advisory

06 Jun 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-06 18:15

Updated : 2024-10-09 15:27


NVD link : CVE-2024-3504

Mitre link : CVE-2024-3504


JSON object : View

Products Affected

lunary

  • lunary