Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-73p4-hh43-4h48

Опубликовано: 20 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

In lunary-ai/lunary before version 1.6.3, the application allows the creation of evaluators without enforcing a unique constraint on the combination of projectId and slug. This allows an attacker to overwrite existing data by submitting a POST request with the same slug as an existing evaluator. The lack of database constraints or application-layer validation to prevent duplicates exposes the application to data integrity issues. This vulnerability can result in corrupted data and potentially malicious actions, impairing the system's functionality.

In lunary-ai/lunary before version 1.6.3, the application allows the creation of evaluators without enforcing a unique constraint on the combination of projectId and slug. This allows an attacker to overwrite existing data by submitting a POST request with the same slug as an existing evaluator. The lack of database constraints or application-layer validation to prevent duplicates exposes the application to data integrity issues. This vulnerability can result in corrupted data and potentially malicious actions, impairing the system's functionality.

EPSS

Процентиль: 13%
0.00043
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-837

Связанные уязвимости

CVSS3: 6.5
nvd
11 месяцев назад

In lunary-ai/lunary before version 1.6.3, the application allows the creation of evaluators without enforcing a unique constraint on the combination of projectId and slug. This allows an attacker to overwrite existing data by submitting a POST request with the same slug as an existing evaluator. The lack of database constraints or application-layer validation to prevent duplicates exposes the application to data integrity issues. This vulnerability can result in corrupted data and potentially malicious actions, impairing the system's functionality.

EPSS

Процентиль: 13%
0.00043
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-837