Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h889-475r-wfmm

Опубликовано: 09 июн. 2025
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Backend.AI Missing Authorization vulnerability

Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI.

NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record.

Пакеты

Наименование

backend.ai

pip
Затронутые версииВерсия исправления

<= 25.3.3

Отсутствует

EPSS

Процентиль: 15%
0.00048
Низкий

8.1 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.1
nvd
8 месяцев назад

Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI.

EPSS

Процентиль: 15%
0.00048
Низкий

8.1 High

CVSS3

Дефекты

CWE-862