CVE-2024-3501
Last modified
CVE-2024-3501 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclusion of single-use tokens in the responses of `GET /v1/users/me` and `GET /v1/users/me/org` API endpoints. These tokens, intended for sensitive operations such as password resets or account verification, are exposed to unauthorized actors, potentially allowing them to perform actions on behalf of the user. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclusion of single-use tokens in the responses of `GET /v1/users/me` and `GET /v1/users/me/org` API endpoints. These tokens, intended for sensitive operations such as password resets or account verification, are exposed to unauthorized actors, potentially allowing them to perform actions on behalf of the user. This issue was addressed in version 1.2.6, where the exposure of single-use tokens in user-facing queries was mitigated.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lunary | Lunary | < 1.2.6 |
References
- https://huntr.com/bounties/8fdfdb9d-10bd-4f00-8004-d5baabc20c6eIssue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-3501?
How severe is CVE-2024-3501?
How do I fix CVE-2024-3501?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-34993In the module "Bulk Export products to Google Merchant-Googl…6.3
- CVE-2024-34994In the module "Channable" (channable) up to version 3.2.1 fr…9.8
- CVE-2024-34995svnWebUI v1.8.3 was discovered to contain an arbitrary file …4.3
- CVE-2024-34997joblib v1.4.2 was discovered to contain a deserialization vu…7.5
- CVE-2024-3500The ElementsKit Pro plugin for WordPress is vulnerable to Lo…8.8
- CVE-2024-35009idccms v1.35 was discovered to contain a Cross-Site Request …8.8
- CVE-2024-35010idccms v1.35 was discovered to contain a Cross-Site Request …8.8
- CVE-2024-35011idccms v1.35 was discovered to contain a Cross-Site Request …5.4
- CVE-2024-35012idccms v1.35 was discovered to contain a Cross-Site Request …6.3
- CVE-2024-3502In lunary-ai/lunary versions up to and including 1.2.5, an i…8.1
- CVE-2024-35039idccms V1.35 was discovered to contain a Cross-Site Request …3.8
- CVE-2024-3504An improper access control vulnerability exists in lunary-ai…6.5
Are you affected by CVE-2024-3501?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
