lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify, and delete prompt templates using an old authorization token. Despite being removed from an organization, these members can still perform operations on prompt templates by sending HTTP requests with their previously captured authorization token. This issue exposes organizations to unauthorized access and manipulation of sensitive template data.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-04-10T17:08:04.411Z
Updated: 2024-04-16T11:10:32.533Z
Reserved: 2024-02-22T11:55:00.476Z
Link: CVE-2024-1741
JSON object: View
NVD Information
Status : Awaiting Analysis
Published: 2024-04-10T17:15:53.483
Modified: 2024-04-15T18:15:09.937
Link: CVE-2024-1741
JSON object: View
Redhat Information
No data.
CWE