PT-2023-13714 · Vantage6 · Vantage6

Frankcorneliusmartin

·

Published

2023-02-28

·

Updated

2023-03-09

·

CVE-2022-39228

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions vantage6 versions prior to 3.8.0
Description vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. It does not inform the user of wrong username/password combination if the username actually exists, in an attempt to prevent bots from obtaining usernames. However, if a wrong password is entered a number of times, the user account is blocked temporarily.
Recommendations Update to version 3.8.0 or later to resolve the issue. As a temporary workaround, consider restricting the number of login attempts to minimize the risk of exploitation.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-39228
GHSA-36GX-9Q6H-G429
PYSEC-2023-313
PYSEC-2023-52

Affected Products

Vantage6