CVE-2026-54533
- EPSS 0.29%
- Veröffentlicht 17.06.2026 22:17:08
- Zuletzt bearbeitet 23.06.2026 15:44:39
vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms can potentially access other algorithms input and output files. Version 5.0.0 fixes the issue. As a workaround, verify and restric...
CVE-2026-54445
- EPSS 0.29%
- Veröffentlicht 17.06.2026 22:14:51
- Zuletzt bearbeitet 23.06.2026 15:44:39
vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is not ideal because attackers know that almost all vantage6 servers have a user...
CVE-2024-27928
- EPSS 0.28%
- Veröffentlicht 17.06.2026 22:12:36
- Zuletzt bearbeitet 23.06.2026 15:44:39
vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, if an attacker hacks into a vantage6 user's email account, they can 1) reset the password via email and then 2) reset the 2FA token via email. This way...
CVE-2024-24769
- EPSS 0.28%
- Veröffentlicht 17.06.2026 22:07:59
- Zuletzt bearbeitet 23.06.2026 15:44:39
vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, users can reset their MFA token via API routes that send them an email. Currently the number of emails that is sent is not limited. This gives attacker...
CVE-2025-43866
- EPSS 0.33%
- Veröffentlicht 12.06.2025 18:15:20
- Zuletzt bearbeitet 17.09.2025 18:44:19
vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The auto-generated key is a UUID1, which is not cryptographically secure as it is predi...
CVE-2025-43863
- EPSS 0.4%
- Veröffentlicht 12.06.2025 17:29:57
- Zuletzt bearbeitet 17.09.2025 18:46:49
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access to an authenticated session, they can try to brute-force the user pass...
CVE-2024-32969
- EPSS 0.32%
- Veröffentlicht 23.05.2024 09:15:09
- Zuletzt bearbeitet 15.04.2026 00:35:42
vantage6 is an open-source infrastructure for privacy preserving analysis. Collaboration administrators can add extra organizations to their collaboration that can extend their influence. For example, organizations that they include can then create n...
CVE-2024-24770
- EPSS 0.39%
- Veröffentlicht 14.03.2024 19:15:49
- Zuletzt bearbeitet 30.07.2025 20:32:42
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. Much like GHSA-45gq-q4xh-cp53, it is possible to find which usernames exist in vantage6 by cal...
CVE-2024-23823
- EPSS 0.31%
- Veröffentlicht 14.03.2024 19:15:49
- Zuletzt bearbeitet 06.08.2025 14:44:09
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. The vantage6 server has no restrictions on CORS settings. It should be possible for people to ...
CVE-2024-21671
- EPSS 0.4%
- Veröffentlicht 30.01.2024 16:15:48
- Zuletzt bearbeitet 21.11.2024 08:54:50
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). It is possible to find out usernames from the response time of login requests. This could aid attacke...