Improper Access Control in lunary-ai/lunary
Vulnerability Description
In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associated with a project to fetch all evaluator data regardless of their role. This vulnerability permits low-privilege users to access potentially sensitive evaluation data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10330
Credits & Attribution
No credits recorded in the NVD database.
References
More from lunary-ai
View All →Affected Vendor
lunary-ai
View all reports →