漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
vantage6 node has an Improper Access Control issue
Vulnerability Description
vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms can potentially access other algorithms input and output files. Version 5.0.0 fixes the issue. As a workaround, verify and restrict the algorithm containers that are allowed to run on the node.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
访问控制不恰当
Vulnerability Title
vantage6 权限许可和访问控制问题漏洞
Vulnerability Description
vantage6是vantage6团队开源的一个用于 Secure Insight eXchange 的开源 priVAcy preserviNg federalTed leArningG 基础架构。 vantage6 5.0.0之前版本存在权限许可和访问控制问题漏洞,该漏洞源于访问控制问题,可能导致恶意算法访问其他算法的输入和输出文件。
CVSS Information
N/A
Vulnerability Type
N/A