Vulnerability Description
In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all projects to users with minimal permissions, such as Viewers or Prompt Editors. This vulnerability allows unauthorized users to retrieve sensitive credentials, which can be used to perform actions on behalf of the project, access private data, and delete resources. The private API keys are exposed in the developer tools when the endpoint is called from the frontend.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lunary | Lunary | 1.4.29 |
Related Weaknesses (CWE)
References
- https://github.com/lunary-ai/lunary/commit/8ba1b8ba2c2c30b1cec30eb5777c1fda670cbPatch
- https://huntr.com/bounties/ffb84fe8-3e60-4200-ac2d-1fd1e1c93e91ExploitThird Party Advisory
FAQ
What is CVE-2024-9099?
CVE-2024-9099 is a vulnerability with a CVSS score of 8.1 (HIGH). In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all projects to users with minimal permissions, such as Viewers or Prompt Editors. This...
How severe is CVE-2024-9099?
CVE-2024-9099 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-9099?
Check the references section above for vendor advisories and patch information. Affected products include: Lunary Lunary.