Description

In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclusion of single-use tokens in the responses of `GET /v1/users/me` and `GET /v1/users/me/org` API endpoints. These tokens, intended for sensitive operations such as password resets or account verification, are exposed to unauthorized actors, potentially allowing them to perform actions on behalf of the user. This issue was addressed in version 1.2.6, where the exposure of single-use tokens in user-facing queries was mitigated.

INFO

Published Date :

2024-11-14T17:34:36.048Z

Last Modified :

2025-01-30T13:09:20.820Z

Source :

@huntr_ai
AFFECTED PRODUCTS

The following products are affected by CVE-2024-3501 vulnerability.

Vendors Products
Lunary
  • Lunary
Lunary-ai
  • Lunary-ai\/lunary
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-3501.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact