CVE-2024-4153

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVSS

No CVSS.

References

No reference.

Configurations

No configuration.

History

07 Jun 2024, 17:15

Type Values Removed Values Added
Summary (en) A vulnerability in lunary-ai/lunary version 1.2.2 allows attackers to bypass user creation limits and potentially evade payment requirements. The issue arises from an undefined behavior when handling input to the API, specifically through a POST request to the /v1/users endpoint. By crafting a request with a new user's email and assigning them an 'admin' role, attackers can invite additional users beyond the set limit. This vulnerability could be exploited to add an unlimited number of users without adhering to the intended restrictions. (en) Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : unknown
CWE CWE-475
References
  • {'url': 'https://huntr.com/bounties/336db0ae-fe33-44b9-ba9d-bf117e0d90c4', 'source': 'security@huntr.dev'}

22 May 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-22 10:15

Updated : 2024-06-07 17:15


NVD link : CVE-2024-4153

Mitre link : CVE-2024-4153

CVE.ORG link : CVE-2024-4153


JSON object : View

Products Affected

No product.

CWE

No CWE.