An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization user to the organization owner. This vulnerability allows the elevated user to delete projects within the organization. The issue is resolved in version 1.2.7.
References
| Link | Resource |
|---|---|
| https://github.com/lunary-ai/lunary/commit/f7507f0949f6634f725ebb8da37c44f76542901f | Patch |
| https://huntr.com/bounties/97958fe4-be21-4b63-966f-8337c72c8e28 | Exploit Third Party Advisory |
| https://github.com/lunary-ai/lunary/commit/f7507f0949f6634f725ebb8da37c44f76542901f | Patch |
| https://huntr.com/bounties/97958fe4-be21-4b63-966f-8337c72c8e28 | Exploit Third Party Advisory |
Configurations
History
15 Oct 2025, 13:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-863 |
Information
Published : 2024-06-06 18:15
Updated : 2025-10-15 13:15
NVD link : CVE-2024-3504
Mitre link : CVE-2024-3504
CVE.ORG link : CVE-2024-3504
JSON object : View
Products Affected
lunary
- lunary
CWE
