CVE-2024-11301

CVSS 3.0 Score 6.5 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 837

Summary

CVE-2024-11301 is a data integrity vulnerability affecting the lunary-ai/lunary application before version 1.6.3. The issue lies in the creation of evaluators without proper uniqueness constraints on projectId and slug, allowing an attacker to overwrite existing data. This lack of validation can lead to corrupted data and potentially malicious actions, resulting in system functionality impairment. The vulnerability exposes the application to data integrity risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share