CVE-2024-6867 Information
Sep 14, 2024
cve
Description
An information disclosure vulnerability exists in the lunary-ai/lunary specifically in the runs/run_id/related endpoint. This endpoint does not verify that the user has the necessary access rights to the run(s) they are accessing. As a result it returns not only the specified run but also all runs that have the run_id listed as their parent run. This issue affects the main branch commit a761d833. The vulnerability allows unauthorized users to obtain information about non-public runs and their related runs given the run_id of a public or non-public run.
Reference
https://huntr.com/bounties/460df515-164c-4435-954b-0233a181545f https://github.com/lunary-ai/lunary/commit/35afd4439464571eb016318cd7b6f85a162225ca
Share on: