vantage6是vantage6开源的一个用于 Secure Insight eXchange 的开源 priVAcy preserviNg federalTed leArningG 基础架构。 vantage6 vantage6-UI 存在信息泄露漏洞,该漏洞源于用于运行 UI 的 docker 镜像泄露了 nginx 版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vantage6 | vantage6-UI | < 4.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-21649 | 8.8 HIGH | Remote code execution |
| CVE-2024-21653 | 6.5 MEDIUM | vantage6 insecure SSH configuration for node and server containers |
| CVE-2024-21671 | 3.7 LOW | vantage6 username timing attack |
| CVE-2024-22193 | 3.5 LOW | vantage6 unencrypted task can be created in encrypted collaboration |
No comments yet