lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify, and delete prompt templates using an old authorization token. Despite being removed from an organization, these members can still perform operations on prompt templates by sending HTTP requests with their previously captured authorization token. This issue exposes organizations to unauthorized access and manipulation of sensitive template data.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2024-04-10T17:08:04.411Z

Updated: 2024-04-16T11:10:32.533Z

Reserved: 2024-02-22T11:55:00.476Z


Link: CVE-2024-1741

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-04-10T17:15:53.483

Modified: 2024-04-15T18:15:09.937


Link: CVE-2024-1741

JSON object: View

cve-icon Redhat Information

No data.

CWE