HomeLunaryCVE-2024-6582

CVE-2024-6582

MEDIUM
4.3CVSS
Published: 2024-09-13
Updated: 2024-11-03
AI Analysis

Description

A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The `saml.ts` file allows a user from one organization to update the Identity Provider (IDP) settings and view the SSO metadata of another organization. This vulnerability can lead to unauthorized access and potential account takeover if the email of a user in the target organization is known.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
network
Complexity
low
Privileges
low
User Action
none
Scope
unchanged
Confidentiality
low
Integrity
none
Availability
none
Weaknesses
CWE-306CWE-306

Metadata

Primary Vendor
LUNARY
Published
9/13/2024
Last Modified
11/3/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

lunary : lunary

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2024-6582 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com