PT-2025-12244 · Unknown · Lunary-Ai/Lunary

CVE-2024-8765

·

Publicado

2025-03-20

·

Atualizado

2025-07-02

CVSS v3.1

7.3

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions lunary-ai/lunary version git afc5df4
Description The privilege check mechanism in lunary-ai/lunary is flawed, allowing unauthenticated attackers to access sensitive endpoints by including "/auth/" in the path. This is because the system incorrectly identifies certain endpoints as public if the path contains "/auth/" anywhere within it. As a result, attackers can obtain and modify sensitive data and utilize other organizations' resources without proper authentication.
Recommendations For version git afc5df4, consider restricting access to sensitive endpoints that may be incorrectly identified as public due to the presence of "/auth/" in their paths, until a proper fix is available. Additionally, as a temporary workaround, avoid using paths that contain "/auth/" for sensitive endpoints to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-8765

Produtos afetados

Lunary-Ai/Lunary