Description

Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is active, even when not owning an authorized email address.


Published: 2024-01-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-16661 Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is active, even when not owning an authorized email address.
History

Tue, 17 Jun 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Mintplexlabs Vector Admin
cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2025-06-17T21:19:29.737Z

Reserved: 2024-01-25T12:23:05.890Z

Link: CVE-2024-0879

cve-icon Vulnrichment

Updated: 2024-08-01T18:18:18.898Z

cve-icon NVD

Status : Modified

Published: 2024-01-25T15:15:07.713

Modified: 2024-11-21T08:47:35.223

Link: CVE-2024-0879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses