Medium severity4.3NVD Advisory· Published Sep 13, 2024· Updated Jun 17, 2026
CVE-2024-6582
CVE-2024-6582
Description
A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The saml.ts file allows a user from one organization to update the Identity Provider (IDP) settings and view the SSO metadata of another organization. This vulnerability can lead to unauthorized access and potential account takeover if the email of a user in the target organization is known.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
lunarynpm | < 1.4.9 | 1.4.9 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/lunary-ai/lunary/commit/1f043d8798ad87346dfe378eea723bff78ad7433nvdPatchWEB
- huntr.com/bounties/251d138c-3911-4a81-96e5-5a4ab59a0b59nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-w73r-8mm4-cfvfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-6582ghsaADVISORY
News mentions
0No linked articles in our index yet.