Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in function sync_tree in hetero_decision_tree_guest.py in WeBank FATE (Federated AI Technology Enabler) 0.1 through 1.4.2 allows attackers to read sensitive information during the training process of machine learning joint modeling.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WeBank Federated AI Technology Enabler 安全漏洞
Vulnerability Description
WeBank Federated AI Technology Enabler是工业级联合学习框架。 WeBank Federated AI Technology Enabler 0.1版本至1.4.2版本存在安全漏洞。攻击者利用该漏洞通过hetero_decision_tree_guest.py的sync_tree函数在机器学习联合建模的训练过程中读取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A