CVE-2024-11137
CVSS 3.0 Score 7.5 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 284
Summary
CVE-2024-11137 is an Insecure Direct Object Reference (IDOR) vulnerability affecting the `PATCH /v1/runs/:id/score` endpoint of lunary-ai/lunary version 1.6.0. An attacker can manipulate the id parameter in the request URL to update the score data of any run, bypassing necessary permissions checks. This issue enables an attacker with a valid account to modify other users' run scores, a significant security concern. This vulnerability has been addressed in version 1.6.1, which implements proper validation to prevent unauthorized modifications.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.