← back
CVE-2024-11300highCWE-639

Improper Access Control in lunary-ai/lunary

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 0.7%
exploitation probability
0.7%top 51% of all CVEs
observed exploitation
nono source reports it
In short

A user could view another user's private prompt data by accessing certain URLs in the Lunary application. This is a serious security problem because it exposes sensitive information that should be kept private.

Technical detail

Improper access control in Lunary versions before 1.6.3 allows horizontal privilege escalation via URL manipulation to retrieve prompt data belonging to other users. The vulnerability requires authentication but no additional pre-conditions; impact includes unauthorized disclosure of confidential prompt information.

Summary generated and translated by AI from the official description.
In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version 1.6.2 and the main branch. The vulnerability allows unauthorized users to view sensitive prompt data by accessing specific URLs, leading to potential exposure of critical information.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H