Логотип exploitDog
bind:CVE-2024-6582
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-6582

Количество 2

Количество 2

nvd логотип

CVE-2024-6582

больше 1 года назад

A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The `saml.ts` file allows a user from one organization to update the Identity Provider (IDP) settings and view the SSO metadata of another organization. This vulnerability can lead to unauthorized access and potential account takeover if the email of a user in the target organization is known.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-w73r-8mm4-cfvf

больше 1 года назад

Withdrawn Advisory: Lunary Improper Authentication vulnerability

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-6582

A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The `saml.ts` file allows a user from one organization to update the Identity Provider (IDP) settings and view the SSO metadata of another organization. This vulnerability can lead to unauthorized access and potential account takeover if the email of a user in the target organization is known.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-w73r-8mm4-cfvf

Withdrawn Advisory: Lunary Improper Authentication vulnerability

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу