CyberRota Analysis
AI-GeneratedAn authentication bypass vulnerability exists in versions of Pig prior to 4.1.0, specifically in the /register/password endpoint, where password verification is improperly handled. This flaw allows remote attackers to overwrite any account credentials, including those of administrative accounts, leading to full administrative control over the affected systems. Organizations using vulnerable versions of Pig should prioritize immediate updates to mitigate the risk of unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to overwrite any account credential including the admin account and gain full administrative control.