In version 1.2.7 of lunary-ai/lunary, any authenticated user, regardless of their role, can change the name of an organization due to improper access control. The function checkAccess() is not implemented, allowing users with the lowest privileges, such as the 'Prompt Editor' role, to modify organization attributes without proper authorization.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2024-06-27T18:46:15.133Z

Updated: 2024-06-27T19:52:27.988Z

Reserved: 2024-06-17T17:44:08.266Z


Link: CVE-2024-6086

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-06-27T19:15:19.533

Modified: 2024-06-27T19:25:12.067


Link: CVE-2024-6086

JSON object: View

cve-icon Redhat Information

No data.

CWE