Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-1738

Опубликовано: 16 апр. 2024
Источник: nvd
CVSS3: 7.5
CVSS3: 7.5
EPSS Низкий

Описание

An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.get route in the evaluations API endpoint. This vulnerability allows unauthorized users to retrieve the results of any organization's evaluation by simply knowing the evaluation ID, due to the lack of project ID verification in the SQL query. As a result, attackers can gain access to potentially private data contained within the evaluation results.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:*
Версия до 1.2.4 (исключая)

EPSS

Процентиль: 45%
0.00228
Низкий

7.5 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 9.9
github
почти 2 года назад

An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.get route in the evaluations API endpoint. This vulnerability allows unauthorized users to retrieve the results of any organization's evaluation by simply knowing the evaluation ID, due to the lack of project ID verification in the SQL query. As a result, attackers can gain access to potentially private data contained within the evaluation results.

EPSS

Процентиль: 45%
0.00228
Низкий

7.5 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-863