CVE-2024-7476
A broken access control vulnerability exists in lunary-ai/lunary versions 1.2.7 through 1.4.2. The vulnerability allows an authenticated attacker to modify any user's templates by sending a crafted HTTP POST request to the /v1/templates/{id}/versions endpoint. This issue is resolved in version 1.4.3.
Vendor
Product
CWE
Yayın Tarihi
2025-03-20 10:15:36
Güncelleme
2025-10-15 13:15:52
Source Identifier
security@huntr.dev
KEV Date Added
-