Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Vantage6: Set admin user and password from environment or configuration
Vulnerability Description
vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is not ideal because attackers know that almost all vantage6 servers have a user with username `root` that probably has admin rights, and the initial password is very weak and it is possible that administrators forget to reset it. Version 5.0.0 fixes the issue. As a workaround, it is possible to delete the `root` user after it has been used to create other users.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Vulnerability Type
响应差异性信息暴露
Vulnerability Title
vantage6 信任管理问题漏洞
Vulnerability Description
vantage6是vantage6团队开源的一个用于 Secure Insight eXchange 的开源 priVAcy preserviNg federalTed leArningG 基础架构。 vantage6 5.0.0之前版本存在安全漏洞,该漏洞源于初始用户root使用弱密码root,可能导致攻击者利用管理员忘记重置密码的风险进行攻击。
CVSS Information
N/A
Vulnerability Type
N/A