Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-286r-8vxx-54v4

Опубликовано: 29 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to manipulation of authentication processes, fraudulent login requests, and theft of user information. Appropriate access controls should be implemented to ensure that the SAML configuration can only be updated by authorized users.

An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to manipulation of authentication processes, fraudulent login requests, and theft of user information. Appropriate access controls should be implemented to ensure that the SAML configuration can only be updated by authorized users.

EPSS

Процентиль: 39%
0.00171
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 9.1
nvd
10 месяцев назад

An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to manipulation of authentication processes, fraudulent login requests, and theft of user information. Appropriate access controls should be implemented to ensure that the SAML configuration can only be updated by authorized users.

CVSS3: 9.1
fstec
10 месяцев назад

Уязвимость платформы для мониторинга, управления и улучшения приложений LLM Lunary, связанная с недостатками контроля доступа, позволяющая нарушителю оказать влияние на конфиденциальность и целостность защищаемой информации

EPSS

Процентиль: 39%
0.00171
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-284