Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-99r4-cjp4-3hmx

Опубликовано: 22 мая 2024
Источник: github
Github: Прошло ревью
CVSS3: 2.7

Описание

vantage6 collaboration admins can extend their influence by expanding the collaboration

Impact

Collaboration administrators can add extra organizations to their collaboration. When doing that, they extend their influence: for instance, for organizations that they include, they can then create new users for which they know the passwords, and use that to read task results of other collaborations that that organization is involved in.

Only relatively trusted users - with access to manage a collaboration - are able to do this, which reduces the impact.

Patches

No

Workarounds

No

Пакеты

Наименование

vantage6

pip
Затронутые версииВерсия исправления

< 4.5.0rc3

4.5.0rc3

EPSS

Процентиль: 42%
0.00197
Низкий

2.7 Low

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 2.7
nvd
больше 1 года назад

vantage6 is an open-source infrastructure for privacy preserving analysis. Collaboration administrators can add extra organizations to their collaboration that can extend their influence. For example, organizations that they include can then create new users for which they know the passwords, and use that to read task results of other collaborations that that organization is involved in. This is only relatively trusted users - with access to manage a collaboration - are able to do this, which reduces the impact. This vulnerability was patched in version 4.5.0rc3.

EPSS

Процентиль: 42%
0.00197
Низкий

2.7 Low

CVSS3

Дефекты

CWE-284