CVE-2024-11137

CVSS 3.0 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 284

Summary

CVE-2024-11137 is an Insecure Direct Object Reference (IDOR) vulnerability affecting the `PATCH /v1/runs/:id/score` endpoint of lunary-ai/lunary version 1.6.0. An attacker can manipulate the id parameter in the request URL to update the score data of any run, bypassing necessary permissions checks. This issue enables an attacker with a valid account to modify other users' run scores, a significant security concern. This vulnerability has been addressed in version 1.6.1, which implements proper validation to prevent unauthorized modifications.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share