
21/5/2024

31/1/2025
CVE-2024-4154: Incorrect Synchronization in lunary-ai/lunary
First published: Tue May 21 2024(Updated: )
In lunary-ai/lunary version 1.2.2, an incorrect synchronization vulnerability allows unprivileged users to rename projects they do not have access to. Specifically, an unprivileged user can send a PATCH request to the project's endpoint with a new name for a project, despite not having the necessary permissions or being assigned to the project. This issue allows for unauthorized modification of project names, potentially leading to confusion or unauthorized access to project resources.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|
| <1.2.26 | |
Never miss a vulnerability like this again
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Frequently Asked Questions
What is the severity of CVE-2024-4154?
CVE-2024-4154 is classified as a medium severity vulnerability due to its impact on project access control.
How do I fix CVE-2024-4154?
To fix CVE-2024-4154, upgrade lunary version to 1.2.26 or later to ensure proper synchronization and access controls.
Who is affected by CVE-2024-4154?
CVE-2024-4154 affects all users of lunary versions prior to 1.2.26, particularly those with unprivileged access.
What does CVE-2024-4154 allow an attacker to do?
CVE-2024-4154 allows unprivileged users to rename projects they do not have access to by sending unauthorized PATCH requests.
When was CVE-2024-4154 disclosed?
CVE-2024-4154 was disclosed as part of the release notes for lunary version 1.2.2.
- agent/title
- agent/first-publish-date
- agent/description
- agent/type
- agent/author
- collector/epss-latest
- source/FIRST
- agent/epss
- collector/mitre-cve
- source/MITRE
- agent/severity
- agent/weakness
- agent/remedy
- agent/source
- agent/event
- agent/references
- agent/last-modified-date
- agent/tags
- agent/softwarecombine
- collector/nvd-api
- source/NVD
- agent/software-canonical-lookup
- vendor/lunary
- canonical/lunary lunary
Contact
SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.coBy using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203