CVE-2025-43866
- EPSS 0.04%
- Veröffentlicht 12.06.2025 18:15:20
- Zuletzt bearbeitet 17.09.2025 18:44:19
vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The auto-generated key is a UUID1, which is not cryptographically secure as it is predi...
CVE-2025-43863
- EPSS 0.05%
- Veröffentlicht 12.06.2025 17:29:57
- Zuletzt bearbeitet 17.09.2025 18:46:49
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access to an authenticated session, they can try to brute-force the user pass...
CVE-2024-32969
- EPSS 0.2%
- Veröffentlicht 23.05.2024 09:15:09
- Zuletzt bearbeitet 21.11.2024 09:16:08
vantage6 is an open-source infrastructure for privacy preserving analysis. Collaboration administrators can add extra organizations to their collaboration that can extend their influence. For example, organizations that they include can then create n...
CVE-2024-24770
- EPSS 0.2%
- Veröffentlicht 14.03.2024 19:15:49
- Zuletzt bearbeitet 30.07.2025 20:32:42
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. Much like GHSA-45gq-q4xh-cp53, it is possible to find which usernames exist in vantage6 by cal...
CVE-2024-23823
- EPSS 0.2%
- Veröffentlicht 14.03.2024 19:15:49
- Zuletzt bearbeitet 06.08.2025 14:44:09
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. The vantage6 server has no restrictions on CORS settings. It should be possible for people to ...
CVE-2024-22193
- EPSS 0.2%
- Veröffentlicht 30.01.2024 16:15:48
- Zuletzt bearbeitet 21.11.2024 08:55:46
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). There are no checks on whether the input is encrypted if a task is created in an encrypted collaborati...
CVE-2024-21671
- EPSS 0.22%
- Veröffentlicht 30.01.2024 16:15:48
- Zuletzt bearbeitet 21.11.2024 08:54:50
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). It is possible to find out usernames from the response time of login requests. This could aid attacke...
CVE-2024-21649
- EPSS 4.81%
- Veröffentlicht 30.01.2024 16:15:47
- Zuletzt bearbeitet 21.11.2024 08:54:48
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Prior to 4.2.0, authenticated users could inject code into algorithm environment variables, resulting ...
CVE-2024-21653
- EPSS 0.23%
- Veröffentlicht 30.01.2024 16:15:47
- Zuletzt bearbeitet 21.11.2024 08:54:48
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Nodes and servers get a ssh config by default that permits root login with password authentication. I...
CVE-2023-47631
- EPSS 0.3%
- Veröffentlicht 14.11.2023 21:15:13
- Zuletzt bearbeitet 21.11.2024 08:30:34
vantage6 is a framework to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). In affected versions a node does not check if an image is allowed to run if a `parent_id` is set. A malicious ...