CVE-2024-9096
CVSS 3.0 Score 7.6 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 285
Summary
CVE-2024-9096 is a vulnerability affecting version 1.4.28 of the lunary package, specifically the /checklists/:id route. This issue allows low-privilege users to manipulate checklists by sending a PATCH request due to insufficient access controls. Unauthorized users, including those without administrative roles, can modify checklists, potentially leading to workflow tampering, disrupted business logic, and erroneous data. This vulnerability poses a significant risk to projects, as it undermines the integrity of essential project data.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.