CVE-2024-5130

Source
https://cve.org/CVERecord?id=CVE-2024-5130
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-5130.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-5130
Withdrawn
2026-05-04T08:46:43.668371Z
Published
2024-06-06T19:16:04.813Z
Modified
2026-05-04T08:46:43.668371Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete any dataset. The vulnerability is due to the lack of proper authorization checks in the dataset deletion endpoint. Specifically, the endpoint does not verify if the provided project ID belongs to the current user, thereby allowing any dataset to be deleted without proper authentication. This issue was fixed in version 1.2.8.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "1.2.8"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-5130.json"