Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-11300

Опубликовано: 20 мар. 2025
Источник: nvd
CVSS3: 8.8
CVSS3: 6.5
EPSS Низкий

Описание

In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version 1.6.2 and the main branch. The vulnerability allows unauthorized users to view sensitive prompt data by accessing specific URLs, leading to potential exposure of critical information.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:*
Версия до 1.6.3 (исключая)

EPSS

Процентиль: 24%
0.0008
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-639
NVD-CWE-Other

Связанные уязвимости

CVSS3: 8.8
github
11 месяцев назад

In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version 1.6.2 and the main branch. The vulnerability allows unauthorized users to view sensitive prompt data by accessing specific URLs, leading to potential exposure of critical information.

EPSS

Процентиль: 24%
0.0008
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-639
NVD-CWE-Other