CVE-2024-3502
CVSS 3.0 Score 9.1 of 10 (critical)
Details
Summary
CVE-2024-3502 is a vulnerability affecting lunary-ai's lunary package versions up to 1.2.5. This issue involves an information disclosure, where account recovery hashes of users are inadvertently exposed to unauthorized actors. This occurs when authenticated users inspect responses from the `GET /v1/users/me` and `GET /v1/users/me/org` endpoints. Although these hashes do not directly reveal user passwords, they represent sensitive information that should not be accessible to unauthorized parties. The potential consequences of this vulnerability include account recovery attacks and other malicious activities. The issue was addressed in version 1.2.6.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.