Impact
GBIF Integrated Publishing Toolkit (IPT) has a missing authentication check during its initial setup process. Until the first reboot, the tool can be accessed without credentials, and a remote attacker can reach the administrative console. By exploiting this oversight, an attacker can obtain full administrative control. The flaw is classified as CWE‑288 (Improper Authentication).
Affected Systems
GBIF Integrated Publishing Toolkit versions prior to 3.3.4 are affected. The vulnerability is present on all supported platforms running these releases.
Risk and Exploitability
The CVSS score of 9.1 indicates a critical severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a remote attacker with network connectivity to the IPT instance, as the description specifies remote authentication bypass; this is inferred from the mention of remote attackers gaining control. Exploitation is only possible until the first reboot, after which authentication enforcement is enabled and the window closes.
OpenCVE Enrichment