CVE-2024-1599

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVSS

No CVSS.

References

No reference.

Configurations

No configuration.

History

07 Jun 2024, 11:15

Type Values Removed Values Added
Summary (en) lunary-ai/lunary version 0.3.0 is vulnerable to unauthorized project creation due to insufficient server-side validation of user account types during project creation. In the free account tier, users are limited to creating only two projects. However, this restriction is enforced only in the web UI and not on the server side, allowing users to bypass the limitation and create an unlimited number of projects without upgrading their account or incurring additional charges. This vulnerability is due to the lack of checks in the project creation endpoint. (en) Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : unknown
CWE CWE-770
References
  • {'url': 'https://github.com/lunary-ai/lunary/commit/48d66a3deef8788fda7621e88f0e3a8a4a1ddeb9', 'source': 'security@huntr.dev'}
  • {'url': 'https://huntr.com/bounties/f1f9e9d6-de5f-48c4-b4f4-fbd192370417', 'source': 'security@huntr.dev'}

10 Apr 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-10 17:15

Updated : 2024-06-07 11:15


NVD link : CVE-2024-1599

Mitre link : CVE-2024-1599

CVE.ORG link : CVE-2024-1599


JSON object : View

Products Affected

No product.

CWE

No CWE.