Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-42cr-cm2x-xxxj

Опубликовано: 10 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

lunary-ai/lunary version 0.3.0 is vulnerable to unauthorized project creation due to insufficient server-side validation of user account types during project creation. In the free account tier, users are limited to creating only two projects. However, this restriction is enforced only in the web UI and not on the server side, allowing users to bypass the limitation and create an unlimited number of projects without upgrading their account or incurring additional charges. This vulnerability is due to the lack of checks in the project creation endpoint.

lunary-ai/lunary version 0.3.0 is vulnerable to unauthorized project creation due to insufficient server-side validation of user account types during project creation. In the free account tier, users are limited to creating only two projects. However, this restriction is enforced only in the web UI and not on the server side, allowing users to bypass the limitation and create an unlimited number of projects without upgrading their account or incurring additional charges. This vulnerability is due to the lack of checks in the project creation endpoint.

5.3 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

nvd
почти 2 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

5.3 Medium

CVSS3

Дефекты

CWE-770