Описание
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). It is possible to find out usernames from the response time of login requests. This could aid attackers in credential attacks. Version 4.2.0 patches this vulnerability.
Ссылки
- Patch
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.2.0 (исключая)
cpe:2.3:a:vantage6:vantage6:*:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.0022
Низкий
3.7 Low
CVSS3
Дефекты
CWE-208
CWE-203
Связанные уязвимости
EPSS
Процентиль: 45%
0.0022
Низкий
3.7 Low
CVSS3
Дефекты
CWE-208
CWE-203