CVE-2024-11301
CVSS 3.0 Score 6.5 of 10 (medium)
Details
Published Mar 20, 2025
CWE ID 837
Summary
CVE-2024-11301 is a data integrity vulnerability affecting the lunary-ai/lunary application before version 1.6.3. The issue lies in the creation of evaluators without proper uniqueness constraints on projectId and slug, allowing an attacker to overwrite existing data. This lack of validation can lead to corrupted data and potentially malicious actions, resulting in system functionality impairment. The vulnerability exposes the application to data integrity risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.