Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-5328

Опубликовано: 06 июн. 2024
Источник: nvd
CVSS3: 8.6
CVSS3: 9.3
EPSS Низкий

Описание

A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the endpoint '/auth/saml/tto/download-idp-xml'. The vulnerability arises due to the application's failure to validate user-supplied URLs before using them in server-side requests. An attacker can exploit this vulnerability by sending a specially crafted request to the affected endpoint, allowing them to make unauthorized requests to internal or external resources. This could lead to the disclosure of sensitive information, service disruption, or further attacks against the network infrastructure. The issue affects the latest version of the application as of the report.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lunary:lunary:-:*:*:*:*:*:*:*

EPSS

Процентиль: 42%
0.00198
Низкий

8.6 High

CVSS3

9.3 Critical

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.6
github
больше 1 года назад

A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the endpoint '/auth/saml/tto/download-idp-xml'. The vulnerability arises due to the application's failure to validate user-supplied URLs before using them in server-side requests. An attacker can exploit this vulnerability by sending a specially crafted request to the affected endpoint, allowing them to make unauthorized requests to internal or external resources. This could lead to the disclosure of sensitive information, service disruption, or further attacks against the network infrastructure. The issue affects the latest version of the application as of the report.

EPSS

Процентиль: 42%
0.00198
Низкий

8.6 High

CVSS3

9.3 Critical

CVSS3

Дефекты

CWE-918