Executive brief
Lunary is an AI platform for managing language model interactions. A flaw in its SAML-based single sign-on (SSO) implementation allowed users to access and modify another organization's identity provider settings, potentially leading to unauthorized account access if an attacker knew a target user's email address.
Technical details
A broken access control vulnerability exists in the saml.ts component that fails to properly validate organization ownership when updating Identity Provider (IDP) settings or viewing SSO metadata. The vulnerability allows authenticated users to target and modify IDP configurations belonging to other organizations (CWE-287, CWE-306). Attack requires network access and valid authentication credentials, but no user interaction. An attacker can escalate to account takeover in the target organization if they know a victim's email. The vulnerability was fixed in version 1.4.9 (commit 1f043d8798ad87346dfe378eea723bff78ad7433).
Affected products
- Lunary Lunary before 1.4.9
Timeline
- 2024-09-13: disclosed: Vulnerability advisory published
- 2024-09-13: patched: Fix available in version 1.4.9
- 2024-11-25: other: Advisory withdrawn from npm package listing (incorrectly linked)