icon

We found results for “

CVE-2024-6867

Date: September 13, 2024

An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the "runs/{run_id}/related" endpoint. This endpoint does not verify that the user has the necessary access rights to the run(s) they are accessing. As a result, it returns not only the specified run but also all runs that have the "run_id" listed as their parent run. This issue affects the main branch, commit a761d833. The vulnerability allows unauthorized users to obtain information about non-public runs and their related runs, given the "run_id" of a public or non-public run.

Language: TYPE_SCRIPT

Severity Score

Severity Score

Weakness Type (CWE)

Insufficient Granularity of Access Control

CWE-1220

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us