PT-2024-25481 · Lunary · Lunary

CVE-2024-3379

·

Published

2024-11-14

·

Updated

2024-11-18

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions lunary-ai/lunary versions 1.2.2 through 1.2.6
Description The issue allows unprivileged users to re-generate the private key for projects they do not have access to. Specifically, a user with a 'Member' role can issue a request to regenerate the private key of a project without having the necessary permissions or being assigned to that project.
Recommendations For versions 1.2.2 through 1.2.6, update to version 1.2.7 to resolve the issue. As a temporary workaround, consider restricting access to project key regeneration functionality to minimize the risk of exploitation.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-3379

Affected Products

Lunary