Логотип exploitDog
bind:CVE-2024-5389
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-5389

Количество 2

Количество 2

nvd логотип

CVE-2024-5389

больше 1 года назад

In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to create, update, get, and delete prompt variations for datasets not owned by their organization. This issue arises due to the application not properly validating the ownership of dataset prompts and their variations against the organization or project of the requesting user. As a result, unauthorized modifications to dataset prompts can occur, leading to altered or removed dataset prompts without proper authorization. This vulnerability impacts the integrity and consistency of dataset information, potentially affecting the results of experiments.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3mwc-2cj7-gx8c

больше 1 года назад

lunary-ai/lunary Access Control Vulnerability in Prompt Variation Management

CVSS3: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-5389

In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to create, update, get, and delete prompt variations for datasets not owned by their organization. This issue arises due to the application not properly validating the ownership of dataset prompts and their variations against the organization or project of the requesting user. As a result, unauthorized modifications to dataset prompts can occur, leading to altered or removed dataset prompts without proper authorization. This vulnerability impacts the integrity and consistency of dataset information, potentially affecting the results of experiments.

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3mwc-2cj7-gx8c

lunary-ai/lunary Access Control Vulnerability in Prompt Variation Management

CVSS3: 9.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу