Vulnerabilities > Lunary > Lunary > 0.1.2

DATE CVE VULNERABILITY TITLE RISK
2024-09-13 CVE-2024-6087 Unspecified vulnerability in Lunary
An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch.
network
low complexity
lunary
6.5
2024-09-13 CVE-2024-6582 Missing Authentication for Critical Function vulnerability in Lunary
A broken access control vulnerability exists in the latest version of lunary-ai/lunary.
network
low complexity
lunary CWE-306
4.3
2024-06-27 CVE-2024-5755 Unspecified vulnerability in Lunary
In lunary-ai/lunary versions <=v1.2.11, an attacker can bypass email validation by using a dot character ('.') in the email address.
network
low complexity
lunary
5.3
2024-06-06 CVE-2024-5128 Unspecified vulnerability in Lunary
An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to and including 1.2.2.
network
low complexity
lunary
8.8
2024-06-06 CVE-2024-5129 Missing Authorization vulnerability in Lunary
A Privilege Escalation Vulnerability exists in lunary-ai/lunary version 1.2.2, where any user can delete any datasets due to missing authorization checks.
network
low complexity
lunary CWE-862
8.2
2024-06-06 CVE-2024-5130 Unspecified vulnerability in Lunary
An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete any dataset.
network
low complexity
lunary
7.5
2024-06-06 CVE-2024-5131 Unspecified vulnerability in Lunary
An Improper Access Control vulnerability exists in the lunary-ai/lunary repository, affecting versions up to and including 1.2.2.
network
low complexity
lunary
6.5
2024-06-06 CVE-2024-5133 Unspecified vulnerability in Lunary
In lunary-ai/lunary version 1.2.4, an account takeover vulnerability exists due to the exposure of password recovery tokens in API responses.
network
low complexity
lunary
8.1
2024-06-06 CVE-2024-3504 Unspecified vulnerability in Lunary
An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization user to the organization owner.
network
low complexity
lunary
6.5
2024-06-06 CVE-2024-5277 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Lunary
In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password token is not invalidated after use.
network
high complexity
lunary CWE-640
7.5