216.73.217.22

CVE-2024-5277

· Published 06/06/2024 18:15 · Modified 06/06/2024 18:15

Labels: CVE-2024-5277 2024-06-06CVE-2024-5277CWE-640[email protected]

Essential information

Published
06/06/2024 18:15
Modified
06/06/2024 18:15
Author
Creator
CVSS
6.4 MEDIUM (v3.0)
CISA KEV
No
CWE
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N

CVSS metrics

Description

In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password token is not invalidated after use. This allows an attacker who compromises the recovery token to repeatedly change the password of a victim's account. The issue lies in the backend's handling of the reset password process, where the token, once used, is not discarded or invalidated, enabling its reuse. This vulnerability could lead to unauthorized account access if an attacker obtains the recovery token.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References