Beveiligingsadvies

CVE-2024-6582

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-09-13 16:11:39
Laatst bijgewerkt 2024-11-03 18:27:25
Toegewezen door @huntr_ai
CVSS-score 6.5
Status PUBLISHED

Beschrijving

A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The `saml.ts` file allows a user from one organization to update the Identity Provider (IDP) settings and view the SSO metadata of another organization. This vulnerability can lead to unauthorized access and potential account takeover if the email of a user in the target organization is known.