CVE-2024-10762

CVSS 3.0 Score 8.1 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 862

Summary

CVE-2024-10762 is a vulnerability affecting the lunary-ai/lunary project before version 1.5.9. The issue lies with the /v1/evaluators/ endpoint, which allows users to delete evaluators of a project via a DELETE request. However, there is insufficient access control in place, enabling low-privilege users to execute this action. This vulnerability results in permanent data loss and can disrupt operations by allowing unauthorized users to delete evaluator data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share