CVE-2024-7476 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A broken access control vulnerability exists in lunary-ai/lunary versions 1.2.7 through 1.4.2. The vulnerability allows an authenticated attacker to modify any…
Medium CVSS: 4.3

CVE-2024-7476

A broken access control vulnerability exists in lunary-ai/lunary versions 1.2.7 through 1.4.2. The vulnerability allows an authenticated attacker to modify any user's templates by sending a crafted HTTP POST request to the /v1/templates/{id}/versions endpoint. This issue is resolved in version 1.4.3.
Vendor
Lunary
Product
Lunary
CWE
CWE-639
Yayın Tarihi
2025-03-20 10:15:36
Güncelleme
2025-10-15 13:15:52
Source Identifier
security@huntr.dev
KEV Date Added
-

Kategoriler

Referanslar