PT-2023-18679 · Vantage6 · Vantage6

Frankcorneliusmartin

·

Publicado

2023-02-28

·

Atualizado

2023-03-10

·

CVE-2023-22738

CVSS v4.0

7.1

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions vantage6 versions prior to 3.8.0
Description The issue concerns a privacy-preserving federated learning infrastructure for secure insight exchange. Assigning existing users to a different organization is currently possible, which may lead to unintended access. If a user from one organization is accidentally assigned to another, they will retain their permissions and might be able to access data they should not be allowed to access.
Recommendations For versions prior to 3.8.0, update to version 3.8.0 to resolve the issue. As a temporary workaround, consider restricting user assignments to prevent accidental transfers between organizations until the update is applied.

Exploit

Correção

Improper Preservation of Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-22738
GHSA-VVJV-97J8-94XH
PYSEC-2023-53

Produtos afetados

Vantage6