PT-2023-28141 · Vantage6 · Vantage6
Frankcorneliusmartin
·
Publicado
2023-10-11
·
Atualizado
2023-10-18
·
CVE-2023-41882
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
vantage6 versions prior to 4.0.0
Description
vantage6 is privacy preserving federated learning infrastructure. The endpoint "/api/collaboration/{id}/task" is used to collect all tasks from a certain collaboration. To get such tasks, a user should have permission to view the collaboration and to view the tasks in it. However, prior to version 4.0.0, it is only checked if the user has permission to view the collaboration.
Recommendations
For versions prior to 4.0.0, update to version 4.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the "/api/collaboration/{id}/task" endpoint until the update is applied.
Exploit
Correção
Incorrect Authorization
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Vantage6