Vulnerabilities > Lunary > High

DATE CVE VULNERABILITY TITLE RISK
2024-11-14 CVE-2024-3760 Unspecified vulnerability in Lunary
In lunary-ai/lunary version 1.2.7, there is a lack of rate limiting on the forgot password page, leading to an email bombing vulnerability.
network
low complexity
lunary
7.5
2024-11-14 CVE-2024-3379 Incorrect Authorization vulnerability in Lunary
In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key for projects they do not have access to.
network
low complexity
lunary CWE-863
8.1
2024-11-14 CVE-2024-3501 Insecure Storage of Sensitive Information vulnerability in Lunary
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclusion of single-use tokens in the responses of `GET /v1/users/me` and `GET /v1/users/me/org` API endpoints.
network
low complexity
lunary CWE-922
8.1
2024-11-14 CVE-2024-3502 Insecure Storage of Sensitive Information vulnerability in Lunary
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists where account recovery hashes of users are inadvertently exposed to unauthorized actors.
network
low complexity
lunary CWE-922
8.1
2024-10-29 CVE-2024-7474 Unspecified vulnerability in Lunary
In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists.
network
low complexity
lunary
8.1
2024-09-13 CVE-2024-6862 Cross-Site Request Forgery (CSRF) vulnerability in Lunary 1.2.34
A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive CORS settings.
network
low complexity
lunary CWE-352
8.1
2024-06-09 CVE-2024-5389 Unspecified vulnerability in Lunary 1.2.13
In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to create, update, get, and delete prompt variations for datasets not owned by their organization.
network
low complexity
lunary
8.1
2024-06-06 CVE-2024-5128 Unspecified vulnerability in Lunary
An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to and including 1.2.2.
network
low complexity
lunary
8.8
2024-06-06 CVE-2024-5129 Missing Authorization vulnerability in Lunary
A Privilege Escalation Vulnerability exists in lunary-ai/lunary version 1.2.2, where any user can delete any datasets due to missing authorization checks.
network
low complexity
lunary CWE-862
8.2
2024-06-06 CVE-2024-5130 Unspecified vulnerability in Lunary
An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete any dataset.
network
low complexity
lunary
7.5