Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-11301

Опубликовано: 20 мар. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

In lunary-ai/lunary before version 1.6.3, the application allows the creation of evaluators without enforcing a unique constraint on the combination of projectId and slug. This allows an attacker to overwrite existing data by submitting a POST request with the same slug as an existing evaluator. The lack of database constraints or application-layer validation to prevent duplicates exposes the application to data integrity issues. This vulnerability can result in corrupted data and potentially malicious actions, impairing the system's functionality.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:*
Версия до 1.6.3 (исключая)

EPSS

Процентиль: 13%
0.00043
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-837

Связанные уязвимости

CVSS3: 6.5
github
11 месяцев назад

In lunary-ai/lunary before version 1.6.3, the application allows the creation of evaluators without enforcing a unique constraint on the combination of projectId and slug. This allows an attacker to overwrite existing data by submitting a POST request with the same slug as an existing evaluator. The lack of database constraints or application-layer validation to prevent duplicates exposes the application to data integrity issues. This vulnerability can result in corrupted data and potentially malicious actions, impairing the system's functionality.

EPSS

Процентиль: 13%
0.00043
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-837