CVE-2024-3501
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-3501 is a newly disclosed vulnerability affecting lunary-ai's lunary package in versions up to 1.2.5. This issue involves an information disclosure weakness, where single-use tokens, meant for secure operations like password resets or account verification, are unintentionally exposed in the responses of `GET /v1/users/me` and `GET /v1/users/me/org` API endpoints. Unauthorized actors can potentially exploit this vulnerability and carry out actions on behalf of affected users. Version 1.2.6 addresses this issue by mitigating the exposure of single-use tokens in user-facing queries.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.