Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xg4q-hj2g-49gr

Опубликовано: 16 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the server fails to treat email addresses as case insensitive, allowing the creation of multiple accounts with the same email address by varying the case of the email characters. For example, accounts for 'abc@gmail.com' and 'Abc@gmail.com' can both be created, leading to potential impersonation and confusion among users.

lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the server fails to treat email addresses as case insensitive, allowing the creation of multiple accounts with the same email address by varying the case of the email characters. For example, accounts for 'abc@gmail.com' and 'Abc@gmail.com' can both be created, leading to potential impersonation and confusion among users.

EPSS

Процентиль: 40%
0.00179
Низкий

7.5 High

CVSS3

Дефекты

CWE-821

Связанные уязвимости

CVSS3: 9.1
nvd
почти 2 года назад

lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the server fails to treat email addresses as case insensitive, allowing the creation of multiple accounts with the same email address by varying the case of the email characters. For example, accounts for 'abc@gmail.com' and 'Abc@gmail.com' can both be created, leading to potential impersonation and confusion among users.

EPSS

Процентиль: 40%
0.00179
Низкий

7.5 High

CVSS3

Дефекты

CWE-821