In lunary-ai/lunary version 1.2.2, the DELETE endpoint located at `packages/backend/src/api/v1/datasets` is vulnerable to unauthorized dataset deletion due to missing authorization and authentication mechanisms. This vulnerability allows any user, even those without a valid token, to delete a dataset by sending a DELETE request to the endpoint. The issue was fixed in version 1.2.8. The impact of this vulnerability is significant as it permits unauthorized users to delete datasets, potentially leading to data loss or disruption of service.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Jan 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lunary
Lunary lunary |
|
CPEs | cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:* | |
Vendors & Products |
Lunary
Lunary lunary |
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-08-01T20:20:01.294Z
Reserved: 2024-04-13T19:09:22.096Z
Link: CVE-2024-3761

Updated: 2024-08-01T20:20:01.294Z

Status : Analyzed
Published: 2024-05-20T09:15:09.497
Modified: 2025-01-10T14:36:20.713
Link: CVE-2024-3761

No data.