Количество 3
Количество 3

CVE-2024-7475
An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to manipulation of authentication processes, fraudulent login requests, and theft of user information. Appropriate access controls should be implemented to ensure that the SAML configuration can only be updated by authorized users.
GHSA-286r-8vxx-54v4
An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to manipulation of authentication processes, fraudulent login requests, and theft of user information. Appropriate access controls should be implemented to ensure that the SAML configuration can only be updated by authorized users.

BDU:2024-11392
Уязвимость платформы для мониторинга, управления и улучшения приложений LLM Lunary, связанная с недостатками контроля доступа, позволяющая нарушителю оказать влияние на конфиденциальность и целостность защищаемой информации
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2024-7475 An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to manipulation of authentication processes, fraudulent login requests, and theft of user information. Appropriate access controls should be implemented to ensure that the SAML configuration can only be updated by authorized users. | CVSS3: 9.1 | 0% Низкий | 10 месяцев назад |
GHSA-286r-8vxx-54v4 An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to manipulation of authentication processes, fraudulent login requests, and theft of user information. Appropriate access controls should be implemented to ensure that the SAML configuration can only be updated by authorized users. | CVSS3: 9.1 | 0% Низкий | 10 месяцев назад | |
![]() | BDU:2024-11392 Уязвимость платформы для мониторинга, управления и улучшения приложений LLM Lunary, связанная с недостатками контроля доступа, позволяющая нарушителю оказать влияние на конфиденциальность и целостность защищаемой информации | CVSS3: 9.1 | 0% Низкий | 10 месяцев назад |
Уязвимостей на страницу