Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fxpx-7wrq-8ggp

Опубликовано: 20 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new members with billing permissions, thereby gaining unauthorized access to billing resources. This issue arises because the user creation endpoint does not restrict admins from inviting users with billing roles. As a result, admins can circumvent the intended access control, posing a risk to the organization's financial resources.

In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new members with billing permissions, thereby gaining unauthorized access to billing resources. This issue arises because the user creation endpoint does not restrict admins from inviting users with billing roles. As a result, admins can circumvent the intended access control, posing a risk to the organization's financial resources.

EPSS

Процентиль: 22%
0.00073
Низкий

7.3 High

CVSS3

Дефекты

CWE-284
CWE-863

Связанные уязвимости

CVSS3: 6.1
nvd
11 месяцев назад

In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new members with billing permissions, thereby gaining unauthorized access to billing resources. This issue arises because the user creation endpoint does not restrict admins from inviting users with billing roles. As a result, admins can circumvent the intended access control, posing a risk to the organization's financial resources.

EPSS

Процентиль: 22%
0.00073
Низкий

7.3 High

CVSS3

Дефекты

CWE-284
CWE-863