← Back

CVE-2024-8765

nvd nist
Published: Mar 20, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.3
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.4
Source: security@huntr.dev (Secondary)

Description

In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies certain endpoints as public if the path contains '/auth/' anywhere within it. This allows unauthenticated attackers to access sensitive endpoints by including '/auth/' in the path. As a result, attackers can obtain and modify sensitive data and utilize other organizations' resources without proper authentication.

Affected (1)

Products: Lunary: Lunary
1 product
Lunary
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.4.23

References (2)

Timeline

No history available yet.