CVE-2024-3379

In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key for projects they do not have access to. Specifically, a user with a 'Member' role can issue a request to regenerate the private key of a project without having the necessary permissions or being assigned to that project. This issue was fixed in version 1.2.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-11-14 18:15

Updated : 2024-11-18 21:30


NVD link : CVE-2024-3379

Mitre link : CVE-2024-3379

CVE.ORG link : CVE-2024-3379


JSON object : View

Products Affected

lunary

  • lunary
CWE
CWE-863

Incorrect Authorization