Vulnerability Description
In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version 1.6.2 and the main branch. The vulnerability allows unauthorized users to view sensitive prompt data by accessing specific URLs, leading to potential exposure of critical information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lunary | Lunary | < 1.6.3 |
Related Weaknesses (CWE)
References
- https://github.com/lunary-ai/lunary/commit/79dc370596d979b756f6ea0250d97a2d02385Patch
- https://huntr.com/bounties/8dca7994-0d92-491e-a419-02adfe23ffa4Exploit
- https://huntr.com/bounties/8dca7994-0d92-491e-a419-02adfe23ffa4Exploit
FAQ
What is CVE-2024-11300?
CVE-2024-11300 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version 1.6.2 and the main branch. The...
How severe is CVE-2024-11300?
CVE-2024-11300 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-11300?
Check the references section above for vendor advisories and patch information. Affected products include: Lunary Lunary.