Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.
History

Wed, 11 Jun 2025 13:30:00 +0000

Type Values Removed Values Added
References

Wed, 11 Jun 2025 12:30:00 +0000

Type Values Removed Values Added
References

Mon, 09 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 09 Jun 2025 17:45:00 +0000

Type Values Removed Values Added
Description Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.
Title Improper access control allows arbitrary account creation
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HiddenLayer

Published: 2025-06-09T17:26:20.835Z

Updated: 2025-06-11T12:12:18.105Z

Reserved: 2025-06-09T13:58:25.617Z

Link: CVE-2025-49652

cve-icon Vulnrichment

Updated: 2025-06-09T18:51:27.590Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-09T18:15:26.897

Modified: 2025-06-12T16:06:47.857

Link: CVE-2025-49652

cve-icon Redhat

No data.