PT-2025-12244 · Unknown · Lunary-Ai/Lunary
CVE-2024-8765
·
Publicado
2025-03-20
·
Atualizado
2025-07-02
CVSS v3.1
7.3
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
lunary-ai/lunary version git afc5df4
Description
The privilege check mechanism in lunary-ai/lunary is flawed, allowing unauthenticated attackers to access sensitive endpoints by including "/auth/" in the path. This is because the system incorrectly identifies certain endpoints as public if the path contains "/auth/" anywhere within it. As a result, attackers can obtain and modify sensitive data and utilize other organizations' resources without proper authentication.
Recommendations
For version git afc5df4, consider restricting access to sensitive endpoints that may be incorrectly identified as public due to the presence of "/auth/" in their paths, until a proper fix is available. Additionally, as a temporary workaround, avoid using paths that contain "/auth/" for sensitive endpoints to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Lunary-Ai/Lunary