Логотип exploitDog
bind:CVE-2024-21653
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-21653

Количество 2

Количество 2

nvd логотип

CVE-2024-21653

около 2 лет назад

The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Nodes and servers get a ssh config by default that permits root login with password authentication. In a proper deployment, the SSH service is not exposed so there is no risk, but not all deployments are ideal. The default should therefore be less permissive. The vulnerability can be mitigated by removing the ssh part from the docker file and rebuilding the docker image. Version 4.2.0 patches the vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2wgc-48g2-cj5w

около 2 лет назад

vantage6 has insecure SSH configuration for node and server containers

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-21653

The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Nodes and servers get a ssh config by default that permits root login with password authentication. In a proper deployment, the SSH service is not exposed so there is no risk, but not all deployments are ideal. The default should therefore be less permissive. The vulnerability can be mitigated by removing the ssh part from the docker file and rebuilding the docker image. Version 4.2.0 patches the vulnerability.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2wgc-48g2-cj5w

vantage6 has insecure SSH configuration for node and server containers

CVSS3: 6.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу