216.73.216.226

CVE-2024-4154

· Published 21/05/2024 18:15 · Modified 21/05/2024 18:15

Labels: CVE-2024-4154 2024-05-21CVE-2024-4154CWE-821[email protected]

Essential information

Published
21/05/2024 18:15
Modified
21/05/2024 18:15
Author
Creator
CVSS
7.1 HIGH (v3.0)
CISA KEV
No
CWE
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

CVSS metrics

Description

In lunary-ai/lunary version 1.2.2, an incorrect synchronization vulnerability allows unprivileged users to rename projects they do not have access to. Specifically, an unprivileged user can send a PATCH request to the project's endpoint with a new name for a project, despite not having the necessary permissions or being assigned to the project. This issue allows for unauthorized modification of project names, potentially leading to confusion or unauthorized access to project resources.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References