Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform.
History

Wed, 11 Jun 2025 13:30:00 +0000

Type Values Removed Values Added
References

Wed, 11 Jun 2025 12:30:00 +0000

Type Values Removed Values Added
References

Mon, 09 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 09 Jun 2025 17:45:00 +0000

Type Values Removed Values Added
Description Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform.
Title Exposure of sensitive Information allows account takeover
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HiddenLayer

Published: 2025-06-09T17:27:00.603Z

Updated: 2025-06-11T12:12:30.504Z

Reserved: 2025-06-09T13:58:25.617Z

Link: CVE-2025-49653

cve-icon Vulnrichment

Updated: 2025-06-09T18:31:55.231Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-09T18:15:27.033

Modified: 2025-06-12T16:06:47.857

Link: CVE-2025-49653

cve-icon Redhat

No data.