CVE-2024-8765
CVSS 3.0 Score 7.3 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 41
Summary
CVE-2024-8765 is a vulnerability affecting the lunary-ai/lunary project in version git afc5df4. This issue involves a flawed privilege check mechanism. Unauthenticated attackers can exploit this vulnerability by manipulating the endpoint paths to include '/auth/' anywhere within them. This misidentification allows attackers to access sensitive endpoints, enabling them to obtain and modify confidential data, as well as utilize other organizations' resources without proper authentication.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.