In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version 1.6.2 and the main branch. The vulnerability allows unauthorized users to view sensitive prompt data by accessing specific URLs, leading to potential exposure of critical information.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version 1.6.2 and the main branch. The vulnerability allows unauthorized users to view sensitive prompt data by accessing specific URLs, leading to potential exposure of critical information. | |
Title | Improper Access Control in lunary-ai/lunary | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:11:19.503Z
Updated: 2025-03-20T14:24:38.973Z
Reserved: 2024-11-16T09:15:59.924Z
Link: CVE-2024-11300

Updated: 2025-03-20T14:24:31.344Z

Status : Awaiting Analysis
Published: 2025-03-20T10:15:24.777
Modified: 2025-03-20T15:15:40.080
Link: CVE-2024-11300

No data.