Vulnerability Description
In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associated with a project to fetch all evaluator data regardless of their role. This vulnerability permits low-privilege users to access potentially sensitive evaluation data.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lunary | Lunary | < 1.5.7 |
Related Weaknesses (CWE)
References
- https://github.com/lunary-ai/lunary/commit/8ba1b8ba2c2c30b1cec30eb5777c1fda670cbPatch
- https://huntr.com/bounties/598ecd65-1723-4fb7-a9aa-9c4f56a5a2aaExploitThird Party Advisory
FAQ
What is CVE-2024-10330?
CVE-2024-10330 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associated with a project to fetch all evaluator data regardless of their role. This vu...
How severe is CVE-2024-10330?
CVE-2024-10330 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-10330?
Check the references section above for vendor advisories and patch information. Affected products include: Lunary Lunary.