logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-5130

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-5130

Description:
An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete any dataset. The vulnerability is due to the lack of proper authorization checks in the dataset deletion endpoint. Specifically, the endpoint does not verify if the provided project ID belongs to the current user, thereby allowing any dataset to be deleted without proper authentication. This issue was fixed in version 1.2.8.
Last updated date:
11/03/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
10/03/2024
Reference url to background

https://huntr.com/bounties/e81a9871-308d-4628-9726-af66643a16fe

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy