CVE-2024-3379

HIGH

lunary-ai/lunary <1.2.7 - Info Disclosure

Title source: llm
STIX 2.1

Description

In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key for projects they do not have access to. Specifically, a user with a 'Member' role can issue a request to regenerate the private key of a project without having the necessary permissions or being assigned to that project. This issue was fixed in version 1.2.7.

References (2)

Core 2

Scores

CVSS v3 8.1
EPSS 0.0039
EPSS Percentile 30.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (1)
lunary/lunary 1.2.2 - 1.2.7
Published Nov 14, 2024
Tracked Since Feb 18, 2026