Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-17553 | BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor |
Github GHSA |
GHSA-hxvr-gg2w-j48x | BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 11 Jun 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 11 Jun 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 09 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Jun 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. | |
| Title | Exposure of sensitive Information allows account takeover | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: HiddenLayer
Published:
Updated: 2025-06-11T12:12:30.504Z
Reserved: 2025-06-09T13:58:25.617Z
Link: CVE-2025-49653
Updated: 2025-06-09T18:31:55.231Z
Status : Deferred
Published: 2025-06-09T18:15:27.033
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-49653
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA