Vulnerabilities > Lunary

DATE CVE VULNERABILITY TITLE RISK
2024-06-08 CVE-2024-4146 Incorrect Authorization vulnerability in Lunary 1.2.13
In lunary-ai/lunary version v1.2.13, an incorrect authorization vulnerability exists that allows unauthorized users to access and manipulate projects within an organization they should not have access to.
network
low complexity
lunary CWE-863
critical
9.8
2024-06-06 CVE-2024-5126 Unspecified vulnerability in Lunary
An improper access control vulnerability exists in the lunary-ai/lunary repository, specifically within the versions.patch functionality for updating prompts.
network
low complexity
lunary
6.5
2024-06-06 CVE-2024-5128 Unspecified vulnerability in Lunary
An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to and including 1.2.2.
network
low complexity
lunary
8.8
2024-06-06 CVE-2024-5129 Missing Authorization vulnerability in Lunary
A Privilege Escalation Vulnerability exists in lunary-ai/lunary version 1.2.2, where any user can delete any datasets due to missing authorization checks.
network
low complexity
lunary CWE-862
8.2
2024-06-06 CVE-2024-5130 Unspecified vulnerability in Lunary
An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete any dataset.
network
low complexity
lunary
7.5
2024-06-06 CVE-2024-5131 Unspecified vulnerability in Lunary
An Improper Access Control vulnerability exists in the lunary-ai/lunary repository, affecting versions up to and including 1.2.2.
network
low complexity
lunary
6.5
2024-06-06 CVE-2024-5133 Unspecified vulnerability in Lunary
In lunary-ai/lunary version 1.2.4, an account takeover vulnerability exists due to the exposure of password recovery tokens in API responses.
network
low complexity
lunary
8.1
2024-06-06 CVE-2024-5248 Unspecified vulnerability in Lunary
In lunary-ai/lunary version 1.2.5, an improper access control vulnerability exists due to a missing permission check in the `GET /v1/users/me/org` endpoint.
network
low complexity
lunary
6.5
2024-06-06 CVE-2024-5328 Unspecified vulnerability in Lunary
A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the endpoint '/auth/saml/tto/download-idp-xml'.
network
low complexity
lunary
critical
9.3
2024-06-06 CVE-2024-5478 Unspecified vulnerability in Lunary 1.2.7
A Cross-site Scripting (XSS) vulnerability exists in the SAML metadata endpoint `/auth/saml/${org?.id}/metadata` of lunary-ai/lunary version 1.2.7.
network
low complexity
lunary
6.1