CVE-2024-10330
CVSS 3.0 Score 6.5 of 10 (medium)
Details
Published Mar 20, 2025
CWE ID 284
Summary
CVE-2024-10330 is a vulnerability affecting the lunary-ai/lunary package version 1.5.6. This issue stems from insufficient access controls on the `/v1/evaluators/` endpoint, allowing users with low privileges to access evaluator data that belongs to other projects. Despite their role limitations, these users can retrieve all evaluator data. The consequences of this vulnerability may involve unauthorized access to sensitive evaluation information.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.