Vulnerabilidades em lunary-ai

71 resultados
Análise Vexday

O ecossistema do lunary-ai acumula 71 CVEs catalogadas, das quais 19 são de severidade crítica — volume considerável para uma plataforma de sua dimensão. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, com nenhum registro confirmado de exploração em produção, o que sugere baixa atratividade imediata para agentes de ameaça oportunistas, embora esse quadro possa mudar rapidamente. A falha mais recorrente é CWE-862 (ausência de verificação de autorização), padrão que historicamente favorece escalonamento de privilégios e acesso não autorizado a recursos; a CVE mais perigosa identificada, CVE-2024-7476, apresenta EPSS de 0,014, indicando probabilidade de exploração ainda contida no curto prazo. A existência de pelo menos um PoC público reforça a necessidade de priorizar a revisão dos controles de autorização, especialmente em ambientes que expõem a plataforma a usuários não confiáveis.

CVE-2024-7476MEDIUMBroken Access Control in lunary-ai/lunaryEPSS 1.4%CVE-2024-7456CRITICALSQL Injection in lunary-ai/lunaryEPSS 1.4%CVE-2024-8765HIGHImproper Path Equivalence Resolution in lunary-ai/lunaryEPSS 0.8%CVE-2024-8763HIGHRegular Expression Denial of Service (ReDoS) in lunary-ai/lunaryEPSS 0.8%CVE-2024-8789HIGHRegular Expression Denial of Service (ReDoS) in lunary-ai/lunaryEPSS 0.8%CVE-2024-8764HIGHImproper Authorization in lunary-ai/lunaryEPSS 0.8%CVE-2024-8998HIGHRegular Expression Denial of Service (ReDoS) in lunary-ai/lunaryEPSS 0.8%CVE-2024-8999CRITICALImproper Access Control in lunary-ai/lunaryEPSS 0.7%CVE-2024-1643CRITICALUnauthorized Organization Access in lunary-ai/lunaryEPSS 0.7%CVE-2024-9095CRITICALImproper Authorization in lunary-ai/lunaryEPSS 0.7%CVE-2024-11300HIGHImproper Access Control in lunary-ai/lunaryEPSS 0.7%CVE-2024-1740CRITICALIncorrect Authorization in lunary-ai/lunaryEPSS 0.6%CVE-2024-7475CRITICALImproper Access Control in lunary-ai/lunaryEPSS 0.6%CVE-2024-4148HIGHRedos (Regular Expression Denial of Service) in lunary-ai/lunaryEPSS 0.6%CVE-2024-1741CRITICALImproper Authorization in lunary-ai/lunaryEPSS 0.6%CVE-2024-1739HIGHCase Insensitive Email Address Validation Vulnerability in lunary-ai/lunaryEPSS 0.6%CVE-2024-10272HIGHBroken Access Control in lunary-ai/lunaryEPSS 0.6%CVE-2024-9099HIGHExposure of Private API Keys in lunary-ai/lunaryEPSS 0.5%CVE-2024-1738HIGHIncorrect Authorization in lunary-ai/lunaryEPSS 0.5%CVE-2024-11301MEDIUMImproper Enforcement of Unique Constraint in lunary-ai/lunaryEPSS 0.5%