CVE-2024-1902 affects lunary-ai/lunary, allowing a removed user to modify an organization's name due to a session reuse vulnerability. This high-severity flaw (CVSS 7.5) requires no user interaction and has low attack complexity, enabling unauthorized changes via an old authorization token. While no active exploitation or public exploit code has been identified, and community discussion is minimal, the potential for unauthorized data modification remains.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.8CPE matchmatch criteria | cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.