CVE-2024-9096

CVSS 3.0 Score 7.6 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 285

Summary

CVE-2024-9096 is a vulnerability affecting version 1.4.28 of the lunary package, specifically the /checklists/:id route. This issue allows low-privilege users to manipulate checklists by sending a PATCH request due to insufficient access controls. Unauthorized users, including those without administrative roles, can modify checklists, potentially leading to workflow tampering, disrupted business logic, and erroneous data. This vulnerability poses a significant risk to projects, as it undermines the integrity of essential project data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share