Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-11137

Опубликовано: 20 мар. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

An Insecure Direct Object Reference (IDOR) vulnerability exists in the PATCH /v1/runs/:id/score endpoint of lunary-ai/lunary version 1.6.0. This vulnerability allows an attacker to update the score data of any run by manipulating the id parameter in the request URL, which corresponds to the runId_score in the database. The endpoint does not sufficiently validate whether the authenticated user has permission to modify the specified runId, enabling an attacker with a valid account to modify other users' runId scores by specifying different id values. This issue was fixed in version 1.6.1.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:*
Версия до 1.6.1 (исключая)

EPSS

Процентиль: 25%
0.00084
Низкий

7.5 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 7.5
github
11 месяцев назад

An Insecure Direct Object Reference (IDOR) vulnerability exists in the `PATCH /v1/runs/:id/score` endpoint of lunary-ai/lunary version 1.6.0. This vulnerability allows an attacker to update the score data of any run by manipulating the id parameter in the request URL, which corresponds to the `runId_score` in the database. The endpoint does not sufficiently validate whether the authenticated user has permission to modify the specified runId, enabling an attacker with a valid account to modify other users' runId scores by specifying different id values. This issue was fixed in version 1.6.1.

EPSS

Процентиль: 25%
0.00084
Низкий

7.5 High

CVSS3

Дефекты

CWE-639