GHSA-w73r-8mm4-cfvf

Suggest an improvement
Source
https://github.com/advisories/GHSA-w73r-8mm4-cfvf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-w73r-8mm4-cfvf/GHSA-w73r-8mm4-cfvf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w73r-8mm4-cfvf
Aliases
  • CVE-2024-6582
Withdrawn
2024-11-25T16:00:57Z
Published
2024-09-13T18:31:48Z
Modified
2026-09-10T03:50:19Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Withdrawn Advisory: Lunary Improper Authentication vulnerability
Details

Withdrawn Advisory

This advisory was incorrectly linked the the npm package lunary. The advisory is valid, but not for that package.

Original Advisory

A broken access control vulnerability exists prior to commit 1f043d8798ad87346dfe378eea723bff78ad7433 of lunary-ai/lunary. The saml.ts file allows a user from one organization to update the Identity Provider (IDP) settings and view the SSO metadata of another organization. This vulnerability can lead to unauthorized access and potential account takeover if the email of a user in the target organization is known.

Database specific
{
    "cwe_ids": [
        "CWE-287",
        "CWE-306"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2024-09-13T19:29:14Z",
    "nvd_published_at": "2024-09-13T17:15:13Z",
    "severity": "HIGH"
}
References

Affected packages

npm / lunary

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.4.9

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-w73r-8mm4-cfvf/GHSA-w73r-8mm4-cfvf.json"