CVE-2025-49652

Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.
Configurations

No configuration.

History

11 Jun 2025, 13:15

Type Values Removed Values Added
References
  • {'url': 'https://hiddenlayer.com/sai_security_advisor/2025-05-backendai-49653/', 'source': '6f8de1f0-f67e-45a6-b68f-98777fdb759c'}
  • () https://hiddenlayer.com/sai_security_advisor/2025-06-backendai/ -
Summary
  • (es) La falta de autenticación en la función de registro de BackendAI de Lablup permite que usuarios arbitrarios creen cuentas de usuario que pueden acceder a datos privados incluso cuando el registro está deshabilitado.

09 Jun 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-09 18:15

Updated : 2025-06-12 16:06


NVD link : CVE-2025-49652

Mitre link : CVE-2025-49652

CVE.ORG link : CVE-2025-49652


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function