CVE-2024-1643

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-1643
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-1643.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-1643
Published
2024-04-10T17:15:52Z
Modified
2025-07-02T00:29:33.600996Z
Summary
[none]
Details

By knowing an organization's ID, an attacker can join the organization without permission and gain the ability to read and modify all data within that organization. This vulnerability allows unauthorized access and modification of sensitive information, posing a significant security risk. The flaw is due to insufficient verification of user permissions when joining an organization.

References

Affected packages

Git / github.com/lunary-ai/lunary

Affected ranges

Type
GIT
Repo
https://github.com/lunary-ai/lunary
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.2.0
v0.2.1
v0.3.0

v1.*

v1.0.0
v1.0.1
v1.0.2
v1.1.0
v1.2.0
v1.2.1