ID |
CVE-2024-3379
|
Sažetak |
In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key for projects they do not have access to. Specifically, a user with a 'Member' role can issue a request to regenerate the private key of a project without having the necessary permissions or being assigned to that project. This issue was fixed in version 1.2.7. |
Reference |
|
CVSS |
Base: | 9.6 |
Impact: | 5.8 |
Exploitability: | 3.1 |
|
Pristup |
Vektor | Složenost | Autentikacija |
NETWORK |
LOW |
LOW |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
HIGH |
HIGH |
NONE |
|
CVSS vektor |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Zadnje važnije ažuriranje |
14-11-2024 - 18:15 |
Objavljeno |
14-11-2024 - 18:15 |