vantage6是vantage6开源的一个用于 Secure Insight eXchange 的开源 priVAcy preserviNg federalTed leArningG 基础架构。 vantage6 4.2.0 版本之前存在安全漏洞,该漏洞源于经过身份验证的用户可以将代码注入算法环境变量,从而导致远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-21653 | 6.5 MEDIUM | vantage6 insecure SSH configuration for node and server containers |
| CVE-2024-21671 | 3.7 LOW | vantage6 username timing attack |
| CVE-2024-22193 | 3.5 LOW | vantage6 unencrypted task can be created in encrypted collaboration |
| CVE-2024-22200 | 3.3 LOW | vantage6-UI docker image leaks software version information |
No comments yet