漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Session Reuse Vulnerability in lunary-ai/lunary
Vulnerability Description
lunary-ai/lunary is vulnerable to a session reuse attack, allowing a removed user to change the organization name without proper authorization. The vulnerability stems from the lack of validation to check if a user is still part of an organization before allowing them to make changes. An attacker can exploit this by using an old authorization token to send a PATCH request, modifying the organization's name even after being removed from the organization. This issue is due to incorrect synchronization and affects the orgs.patch route.
CVSS Information
N/A
Vulnerability Type
不正确的同步机制
Vulnerability Title
lunary 安全漏洞
Vulnerability Description
Lunary是lunary开源的一个 LLM 的生产工具包。 lunary存在安全漏洞,该漏洞源于允许已删除的用户在未经授权的情况下更改组织名称。
CVSS Information
N/A
Vulnerability Type
N/A