Description
In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to create, update, get, and delete prompt variations for datasets not owned by their organization. This issue arises due to the application not properly validating the ownership of dataset prompts and their variations against the organization or project of the requesting user. As a result, unauthorized modifications to dataset prompts can occur, leading to altered or removed dataset prompts without proper authorization. This vulnerability impacts the integrity and consistency of dataset information, potentially affecting the results of experiments.
INFO
Published Date :
2024-06-09T22:22:38.179Z
Last Modified :
2024-08-01T21:11:12.487Z
Source :
@huntr_ai
AFFECTED PRODUCTS
The following products are affected by CVE-2024-5389 vulnerability.
| Vendors | Products |
|---|---|
| Lunary |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-5389.