U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-5389

Change History

New CVE Received from huntr.dev 6/09/2024 7:15:50 PM

Action Type Old Value New Value
Added Description

								
							
							
						
In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to create, update, get, and delete prompt variations for datasets not owned by their organization. This issue arises due to the application not properly validating the ownership of dataset prompts and their variations against the organization or project of the requesting user. As a result, unauthorized modifications to dataset prompts can occur, leading to altered or removed dataset prompts without proper authorization. This vulnerability impacts the integrity and consistency of dataset information, potentially affecting the results of experiments.
Added CVSS V3

								
							
							
						
huntr.dev AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Added CWE

								
							
							
						
huntr.dev CWE-1220
Added Reference

								
							
							
						
huntr.dev https://huntr.com/bounties/3ca5309f-5615-4d5b-8043-968af220d7a2 [No types assigned]