CVE-2024-22193

The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). There are no checks on whether the input is encrypted if a task is created in an encrypted collaboration. Therefore, a user may accidentally create a task with sensitive input data that will then be stored unencrypted in a database. Users should ensure they set the encryption setting correctly. This vulnerability is patched in 4.2.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vantage6:vantage6:*:*:*:*:*:*:*:*

History

08 Feb 2024, 16:41

Type Values Removed Values Added
Summary
  • (es) La tecnología vantage6 permite gestionar e implementar tecnologías que mejoran la privacidad, como el Federated Learning (FL) y la Multi-Party Computation (MPC). No se comprueba si la entrada está cifrada si se crea una tarea en una colaboración cifrada. Por lo tanto, un usuario puede crear accidentalmente una tarea con datos de entrada confidenciales que luego se almacenarán sin cifrar en una base de datos. Los usuarios deben asegurarse de configurar correctamente la configuración de cifrado. Esta vulnerabilidad está parcheada en 4.2.0.
CVSS v2 : unknown
v3 : 3.5
v2 : unknown
v3 : 4.3
References () https://github.com/vantage6/vantage6/commit/6383283733b81abfcacfec7538dc4dc882e98074 - () https://github.com/vantage6/vantage6/commit/6383283733b81abfcacfec7538dc4dc882e98074 - Patch
References () https://github.com/vantage6/vantage6/security/advisories/GHSA-rjmv-52mp-gjrr - () https://github.com/vantage6/vantage6/security/advisories/GHSA-rjmv-52mp-gjrr - Vendor Advisory
First Time Vantage6 vantage6
Vantage6
CPE cpe:2.3:a:vantage6:vantage6:*:*:*:*:*:*:*:*

30 Jan 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-30 16:15

Updated : 2024-02-08 16:41


NVD link : CVE-2024-22193

Mitre link : CVE-2024-22193

CVE.ORG link : CVE-2024-22193


JSON object : View

Products Affected

vantage6

  • vantage6
CWE
CWE-922

Insecure Storage of Sensitive Information