Critical severity9.1NVD Advisory· Published Oct 29, 2024· Updated Jun 17, 2026
CVE-2024-7475
CVE-2024-7475
Description
An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to manipulation of authentication processes, fraudulent login requests, and theft of user information. Appropriate access controls should be implemented to ensure that the SAML configuration can only be updated by authorized users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/lunary-ai/lunary/commit/8f563c77d8614a72980113f530c7a9ec15a5f8d5nvdPatch
- huntr.com/bounties/78c824f7-3b6d-443d-bb76-0f8031c6c126nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.