Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pcfp-5frw-85m7

Опубликовано: 16 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.get route in the evaluations API endpoint. This vulnerability allows unauthorized users to retrieve the results of any organization's evaluation by simply knowing the evaluation ID, due to the lack of project ID verification in the SQL query. As a result, attackers can gain access to potentially private data contained within the evaluation results.

An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.get route in the evaluations API endpoint. This vulnerability allows unauthorized users to retrieve the results of any organization's evaluation by simply knowing the evaluation ID, due to the lack of project ID verification in the SQL query. As a result, attackers can gain access to potentially private data contained within the evaluation results.

EPSS

Процентиль: 45%
0.00228
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.5
nvd
почти 2 года назад

An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.get route in the evaluations API endpoint. This vulnerability allows unauthorized users to retrieve the results of any organization's evaluation by simply knowing the evaluation ID, due to the lack of project ID verification in the SQL query. As a result, attackers can gain access to potentially private data contained within the evaluation results.

EPSS

Процентиль: 45%
0.00228
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-863