CVE-2025-49651

Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI.
Configurations

No configuration.

History

11 Jun 2025, 13:15

Type Values Removed Values Added
Summary
  • (es) La falta de autorización en BackendAI de Lablup permite a los atacantes tomar el control de todas las sesiones activas, accediendo, robando o alterando cualquier dato accesible en la sesión. Esta vulnerabilidad existe en todas las versiones actuales de BackendAI.
References
  • {'url': 'https://hiddenlayer.com/sai_security_advisor/2025-05-backendai-49653/', 'source': '6f8de1f0-f67e-45a6-b68f-98777fdb759c'}
  • () https://hiddenlayer.com/sai_security_advisor/2025-06-backendai/ -

09 Jun 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-09 18:15

Updated : 2025-06-12 16:06


NVD link : CVE-2025-49651

Mitre link : CVE-2025-49651

CVE.ORG link : CVE-2025-49651


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization