CRITICAL
Improper access control allows arbitrary account creation
Published Jun 9, 2025
9.8
CRITICALCVSS 3.1
EPSS 0.43%
Description
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.
Affected products
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-17554 Advisory
- https://github.com/advisories/GHSA-ww28-4m4v-cq4j Advisory
- https://github.com/lablup/backend.ai/commit/37fc8f70f9bad2dd01fe2e288f9006e96f9914ed
- https://github.com/lablup/backend.ai/commit/b6d3ddd9e285a7ce59722a37585b9298681eb82f
- https://github.com/lablup/backend.ai/commit/d7704f506e319acff205d91bfca6e2ca92939983
- https://hiddenlayer.com/sai_security_advisor/2025-05-backendai-49653
- https://hiddenlayer.com/sai_security_advisor/2025-06-backendai
- https://nvd.nist.gov/vuln/detail/CVE-2025-49652
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner HiddenLayer
Published Jun 9, 2025
Updated Jun 11, 2025
Reserved Jun 9, 2025
Link CVE-2025-49652
CISA Vulnrichment
Updated Jun 9, 2025
ENISA EUVD
EUVD-2025-17554 GHSA-WW28-4M4V-CQ4J Assigner HiddenLayer
Published Jun 9, 2025
Updated Jun 11, 2025
Exploited since n/a
Link EUVD-2025-17554