CVE-2024-10273
CVSS 3.0 Score 6.5 of 10 (medium)
Details
Published Mar 20, 2025
CWE ID 269
Summary
CVE-2024-10273 is a privilege escalation vulnerability affecting version 1.5.0 of the lunary package, specifically in the models.ts file. Unprivileged users with viewer roles can bypass privilege checks and modify models owned by others via the PATCH endpoint. This issue poses a significant risk as it allows unauthorized users to alter critical resources, potentially compromising the system's integrity and reliability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.