CVE-2024-3504

An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization user to the organization owner. This vulnerability allows the elevated user to delete projects within the organization. The issue is resolved in version 1.2.7.
Configurations

No configuration.

History

No history.

Information

Published : 2024-06-06 18:15

Updated : 2024-06-07 14:56


NVD link : CVE-2024-3504

Mitre link : CVE-2024-3504

CVE.ORG link : CVE-2024-3504


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control