CVE-2024-9095
CRITICALlunary v1.4.28 - Authenticated Missing Authorization in BigQuery API Route
Title source: llmDescription
In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to create a Datastream to Google BigQuery and export the entire database. This includes sensitive data such as password hashes and secret API keys. The route is protected by a config check (`config.DATA_WAREHOUSE_EXPORTS_ALLOWED`), but it does not verify the user's access level or implement any access control middleware. This vulnerability can lead to the extraction of sensitive data, disruption of services, credential compromise, and service integrity breaches.
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/e242a92e-da41-440d-b718-3de91e4b4eac
Scores
CVSS v3
9.8
EPSS
0.0068
EPSS Percentile
47.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-862
Status
published
Products (1)
lunary/lunary
1.4.28
Published
Mar 20, 2025
Tracked Since
Feb 18, 2026