CVE-2024-1666

CVSS V2 None CVSS V3 None
Description
In lunary-ai/lunary version 1.0.0, an authorization flaw exists that allows unauthorized radar creation. The vulnerability stems from the lack of server-side checks to verify if a user is on a free account during the radar creation process, which is only enforced in the web UI. As a result, attackers can bypass the intended account upgrade requirement by directly sending crafted requests to the server, enabling the creation of an unlimited number of radars without payment.
Overview
  • CVE ID
  • CVE-2024-1666
  • Assigner
  • @huntr_ai
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-04-16T00:00:13.999Z
  • Last Modified Date
  • 2024-04-16T11:10:47.172Z
History
Created Old Value New Value Data Type Notes
2024-06-26 05:58:54 Added to TrackCVE