CVE-2024-10762
CVSS 3.0 Score 8.1 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 862
Summary
CVE-2024-10762 is a vulnerability affecting the lunary-ai/lunary project before version 1.5.9. The issue lies with the /v1/evaluators/ endpoint, which allows users to delete evaluators of a project via a DELETE request. However, there is insufficient access control in place, enabling low-privilege users to execute this action. This vulnerability results in permanent data loss and can disrupt operations by allowing unauthorized users to delete evaluator data.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.