PT-2024-37914 · Lunary Ai · Lunary-Ai

CVE-2024-6867

·

Published

2024-09-13

·

Updated

2024-09-19

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions lunary-ai/lunary versions up to 1.4.9
Description An information disclosure issue exists in the runs/{run id}/related endpoint, which does not verify user access rights to the run(s) being accessed. This allows unauthorized users to obtain information about non-public runs and their related runs, given the run id of a public or non-public run.
Recommendations For versions up to 1.4.9, upgrade lunary-ai to mitigate the threat. As a temporary workaround, consider restricting access to the runs/{run id}/related endpoint until a patch is available. Avoid using the run id parameter in the affected endpoint to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6867
GHSA-9JMP-J63G-8X6M

Affected Products

Lunary-Ai