CVE-2025-49652
Improper access control allows arbitrary account creation
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Lablup · BackendAI¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →