Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jgvw-vmvx-q85m

Опубликовано: 18 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

An Insecure Direct Object Reference (IDOR) vulnerability was identified in the POST /v1/templates endpoint of the Lunary API, affecting versions up to 0.8.8. This vulnerability allows authenticated users to create templates in another user's project by altering the projectId query parameter. The root cause of this issue is the absence of server-side validation to ensure that the authenticated user owns the specified projectId. The vulnerability has been addressed in version 1.9.23.

An Insecure Direct Object Reference (IDOR) vulnerability was identified in the POST /v1/templates endpoint of the Lunary API, affecting versions up to 0.8.8. This vulnerability allows authenticated users to create templates in another user's project by altering the projectId query parameter. The root cause of this issue is the absence of server-side validation to ensure that the authenticated user owns the specified projectId. The vulnerability has been addressed in version 1.9.23.

EPSS

Процентиль: 8%
0.00028
Низкий

7.7 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.7
nvd
6 месяцев назад

An Insecure Direct Object Reference (IDOR) vulnerability was identified in the `POST /v1/templates` endpoint of the Lunary API, affecting versions up to 0.8.8. This vulnerability allows authenticated users to create templates in another user's project by altering the `projectId` query parameter. The root cause of this issue is the absence of server-side validation to ensure that the authenticated user owns the specified `projectId`. The vulnerability has been addressed in version 1.9.23.

EPSS

Процентиль: 8%
0.00028
Низкий

7.7 High

CVSS3

Дефекты

CWE-284