Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-44q8-52gx-27g8

Опубликовано: 20 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version 1.6.2 and the main branch. The vulnerability allows unauthorized users to view sensitive prompt data by accessing specific URLs, leading to potential exposure of critical information.

In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version 1.6.2 and the main branch. The vulnerability allows unauthorized users to view sensitive prompt data by accessing specific URLs, leading to potential exposure of critical information.

EPSS

Процентиль: 24%
0.0008
Низкий

8.8 High

CVSS3

Дефекты

CWE-284
CWE-639

Связанные уязвимости

CVSS3: 6.5
nvd
11 месяцев назад

In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version 1.6.2 and the main branch. The vulnerability allows unauthorized users to view sensitive prompt data by accessing specific URLs, leading to potential exposure of critical information.

EPSS

Процентиль: 24%
0.0008
Низкий

8.8 High

CVSS3

Дефекты

CWE-284
CWE-639