CVE-2024-10273

CVSS 3.0 Score 6.5 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 269

Summary

CVE-2024-10273 is a privilege escalation vulnerability affecting version 1.5.0 of the lunary package, specifically in the models.ts file. Unprivileged users with viewer roles can bypass privilege checks and modify models owned by others via the PATCH endpoint. This issue poses a significant risk as it allows unauthorized users to alter critical resources, potentially compromising the system's integrity and reliability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share