In lunary-ai/lunary versions <=v1.2.11, an attacker can bypass email validation by using a dot character ('.') in the email address. This allows the creation of multiple accounts with essentially the same email address (e.g., 'attacker123@gmail.com' and 'attacker.123@gmail.com'), leading to incorrect synchronization and potential security issues.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2024-06-27T18:45:48.607Z

Updated: 2024-06-28T15:07:07.776Z

Reserved: 2024-06-07T17:02:33.877Z


Link: CVE-2024-5755

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-06-27T19:15:16.400

Modified: 2024-06-27T19:25:12.067


Link: CVE-2024-5755

JSON object: View

cve-icon Redhat Information

No data.

CWE