backend.ai-agent@26.2.0rc1

Backend.AI Agent

Direct Vulnerabilities

Known vulnerabilities in the backend.ai-agent package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Missing Authorization

Affected versions of this package are vulnerable to Missing Authorization due to improper security controls. An attacker can gain unauthorized access and control over active sessions by exploiting this security oversight.

Note: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from 7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record.

How to fix Missing Authorization?

There is no fixed version for backend.ai-agent.

[0,)
  • H
Missing Authentication for Critical Function

Affected versions of this package are vulnerable to Missing Authentication for Critical Function due to missing authentication in the registration feature. An attacker with a registered user account can create user accounts that can access private data even when registration is disabled.

Note: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from 7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record.

How to fix Missing Authentication for Critical Function?

There is no fixed version for backend.ai-agent.

[0,)
  • H
Improperly Implemented Security Check for Standard

Affected versions of this package are vulnerable to Improperly Implemented Security Check for Standard due to the exposure of sensitive data in active sessions. An attacker can retrieve credentials for users on the management platform by exploiting this vulnerability.

Note: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from 7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record.

How to fix Improperly Implemented Security Check for Standard?

There is no fixed version for backend.ai-agent.

[0,)