Skip to content

Commit f35904c

Browse files
1 parent 57275f7 commit f35904c

1 file changed

Lines changed: 6 additions & 2 deletions

File tree

advisories/github-reviewed/2025/06/GHSA-hxvr-gg2w-j48x/GHSA-hxvr-gg2w-j48x.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-hxvr-gg2w-j48x",
4-
"modified": "2025-06-11T17:38:06Z",
4+
"modified": "2026-01-21T14:46:33Z",
55
"published": "2025-06-09T18:32:17Z",
66
"aliases": [
77
"CVE-2025-49653"
88
],
99
"summary": "BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor",
10-
"details": "Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform.",
10+
"details": "Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform.\n\nNOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record.",
1111
"severity": [
1212
{
1313
"type": "CVSS_V3",
@@ -40,6 +40,10 @@
4040
"type": "ADVISORY",
4141
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49653"
4242
},
43+
{
44+
"type": "WEB",
45+
"url": "https://github.com/lablup/backend.ai/pull/7587"
46+
},
4347
{
4448
"type": "PACKAGE",
4549
"url": "https://github.com/lablup/backend.ai"

0 commit comments

Comments
 (0)