Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w73r-8mm4-cfvf

Опубликовано: 13 сент. 2024
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Withdrawn Advisory: Lunary Improper Authentication vulnerability

Withdrawn Advisory

This advisory was incorrectly linked the the npm package lunary. The advisory is valid, but not for that package.

Original Advisory

A broken access control vulnerability exists prior to commit 1f043d8798ad87346dfe378eea723bff78ad7433 of lunary-ai/lunary. The saml.ts file allows a user from one organization to update the Identity Provider (IDP) settings and view the SSO metadata of another organization. This vulnerability can lead to unauthorized access and potential account takeover if the email of a user in the target organization is known.

Пакеты

Наименование

lunary

npm
Затронутые версииВерсия исправления

< 1.4.9

1.4.9

EPSS

Процентиль: 34%
0.00135
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-287
CWE-306

Связанные уязвимости

CVSS3: 4.3
nvd
больше 1 года назад

A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The `saml.ts` file allows a user from one organization to update the Identity Provider (IDP) settings and view the SSO metadata of another organization. This vulnerability can lead to unauthorized access and potential account takeover if the email of a user in the target organization is known.

EPSS

Процентиль: 34%
0.00135
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-287
CWE-306