CVE-2024-10273 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify models owned by others. The PATCH endpo…
Medium CVSS: 6.5

CVE-2024-10273

In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify models owned by others. The PATCH endpoint for models does not have appropriate privilege checks, enabling low-privilege users to update models they should not have access to modify. This vulnerability could lead to unauthorized changes in critical resources, affecting the integrity and reliability of the system.
Vendor
Lunary
Product
Lunary
CWE
CWE-863
Yayın Tarihi
2025-03-20 10:15:15
Güncelleme
2025-10-15 13:15:34
Source Identifier
security@huntr.dev
KEV Date Added
-

Kategoriler

Referanslar