First published: Tue Oct 29 2024(Updated: )
An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability allows an authenticated user to update other users' prompts by manipulating the 'id' parameter in the request. The issue is fixed in version 1.4.3.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
lunary lunary | =1.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7473 is classified as a medium severity vulnerability due to its potential impact on user data integrity.
To fix CVE-2024-7473, upgrade to Lunary version 1.3.3 or later where the vulnerability has been addressed.
CVE-2024-7473 affects users of Lunary version 1.3.2 who have authenticated access to the 'Evaluations' function.
CVE-2024-7473 allows an authenticated user to manipulate the 'id' parameter and update prompts belonging to other users.
Yes, a patch for CVE-2024-7473 is included in Lunary version 1.3.3 and later.