CVE-2024-10330

CVSS 3.0 Score 6.5 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 284

Summary

CVE-2024-10330 is a vulnerability affecting the lunary-ai/lunary package version 1.5.6. This issue stems from insufficient access controls on the `/v1/evaluators/` endpoint, allowing users with low privileges to access evaluator data that belongs to other projects. Despite their role limitations, these users can retrieve all evaluator data. The consequences of this vulnerability may involve unauthorized access to sensitive evaluation information.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share