CVE-2024-5277

HIGH

lunary < 1.4.9 - Weak Password Recovery Mechanism via Reusable Reset Token

Title source: llm
STIX 2.1

Description

In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password token is not invalidated after use. This allows an attacker who compromises the recovery token to repeatedly change the password of a victim's account. The issue lies in the backend's handling of the reset password process, where the token, once used, is not discarded or invalidated, enabling its reuse. This vulnerability could lead to unauthorized account access if an attacker obtains the recovery token.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0035
EPSS Percentile 26.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-640
Status published
Products (1)
lunary/lunary < 1.4.9
Published Jun 06, 2024
Tracked Since Feb 18, 2026