github.com
https://github.com/pypa/advisory-database/tree/main/vulns/vantage6/PYSEC-2023-201.yaml CVE-2023-41882
vantage6 Improper Access Control vulnerability
Description
vantage6 is privacy preserving federated learning infrastructure. The endpoint /api/collaboration/{id}/task is used to collect all tasks from a certain collaboration. To get such tasks, a user should have permission to view the collaboration and to view the tasks in it. However, prior to version 4.0.0, it is only checked if the user has permission to view the collaboration. Version 4.0.0 contains a patch. There are no known workarounds.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 17, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
vantage6Browse vantage6 / vantage6 | CVE List | < 4.0.0 | affected |
vantage6Browse PyPI / vantage6 | GitHub Advisory | Before 4.0.0 · Fixed in 4.0.0 | affected |
References
7github.com
https://github.com/vantage6/vantage6 github.com
https://github.com/vantage6/vantage6/blob/0682c4288f43fee5bcc72dc448cdd99bd7e57f76/docs/release_notes.rst github.com
https://github.com/vantage6/vantage6/commit/86564e103cbac5238ce2fe392e3357e0e8c20220 github.com
https://github.com/vantage6/vantage6/pull/711 github.comConfirmation
https://github.com/vantage6/vantage6/security/advisories/GHSA-gc57-xhh5-m94r nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-41882