Nvidia

Nvflare

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 28.04.2026 17:46:15
  • Zuletzt bearbeitet 04.05.2026 14:33:23

NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may lead to information disclosure.

  • EPSS 0.11%
  • Veröffentlicht 28.04.2026 17:45:40
  • Zuletzt bearbeitet 04.05.2026 14:33:41

NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit of this vulnerability might lead to code execution.

  • EPSS 0.13%
  • Veröffentlicht 28.04.2026 17:44:51
  • Zuletzt bearbeitet 04.05.2026 14:34:01

NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to pr...

  • EPSS 22.45%
  • Veröffentlicht 29.08.2022 03:15:07
  • Zuletzt bearbeitet 21.11.2024 07:09:56

NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and...

  • EPSS 2.44%
  • Veröffentlicht 01.07.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 07:04:49

NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pickle and no safe deserialization. The deserialization of Untrusted Data may allow an unprivileged network atta...

  • EPSS 2.44%
  • Veröffentlicht 01.07.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 07:04:50

NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load(). The deserialization of Untrusted Data, may allow an unprivileged network attacker to cause Remote...