PT-2024-18997 · Vantage6 · Vantage6

Bartvanb

·

Published

2024-01-30

·

Updated

2024-02-08

·

CVE-2024-21649

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vantage6 versions prior to 4.2.0
Description The vantage6 technology is used to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Authenticated users could inject code into algorithm environment variables, resulting in remote code execution.
Recommendations For versions prior to 4.2.0, update to version 4.2.0 to resolve the issue. As a temporary workaround, consider restricting access to algorithm environment variables to prevent code injection until the update is applied.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-21649
GHSA-W9H2-PX87-74VX
PYSEC-2024-30

Affected Products

Vantage6