CVE-2024-10275

CVSS 3.0 Score 7.3 of 10 (high)

Details

Published Mar 20, 2025

Summary

CVE-2024-10275 is a privilege escalation vulnerability affecting version 1.5.5 of lunary-ai/lunary. Admins who lack direct permissions to access billing resources can manipulate user permissions, granting themselves billing access. This bypasses intended role-based access control, enabling administrators to manage billing information unauthorized, potentially leading to financial risks for organizations. Only 'owner' role users should be permitted to invite members with billing permissions to maintain security.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share