Логотип exploitDog
bind:CVE-2024-6086
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-6086

Количество 2

Количество 2

nvd логотип

CVE-2024-6086

больше 1 года назад

In version 1.2.7 of lunary-ai/lunary, any authenticated user, regardless of their role, can change the name of an organization due to improper access control. The function checkAccess() is not implemented, allowing users with the lowest privileges, such as the 'Prompt Editor' role, to modify organization attributes without proper authorization.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-cqgr-63wx-2gm4

больше 1 года назад

In version 1.2.7 of lunary-ai/lunary, any authenticated user, regardless of their role, can change the name of an organization due to improper access control. The function checkAccess() is not implemented, allowing users with the lowest privileges, such as the 'Prompt Editor' role, to modify organization attributes without proper authorization.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-6086

In version 1.2.7 of lunary-ai/lunary, any authenticated user, regardless of their role, can change the name of an organization due to improper access control. The function checkAccess() is not implemented, allowing users with the lowest privileges, such as the 'Prompt Editor' role, to modify organization attributes without proper authorization.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-cqgr-63wx-2gm4

In version 1.2.7 of lunary-ai/lunary, any authenticated user, regardless of their role, can change the name of an organization due to improper access control. The function checkAccess() is not implemented, allowing users with the lowest privileges, such as the 'Prompt Editor' role, to modify organization attributes without proper authorization.

CVSS3: 5.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу