vantage6是vantage6开源的一个用于 Secure Insight eXchange 的开源 priVAcy preserviNg federalTed leArningG 基础架构。 vantage6 4.2.0 版本之前存在访问控制错误漏洞,该漏洞源于节点和服务器默认获得 ssh 配置,允许使用密码身份验证进行 root 登录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-21649 | 8.8 HIGH | Remote code execution |
| CVE-2024-21671 | 3.7 LOW | vantage6 username timing attack |
| CVE-2024-22193 | 3.5 LOW | vantage6 unencrypted task can be created in encrypted collaboration |
| CVE-2024-22200 | 3.3 LOW | vantage6-UI docker image leaks software version information |
No comments yet