CVE-2023-22738
Last modified
CVE-2023-22738 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Assigning existing users to a different organizations is currently possible. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Assigning existing users to a different organizations is currently possible. It may lead to unintended access: if a user from organization A is accidentally assigned to organization B, they will retain their permissions and therefore might be able to access stuff they should not be allowed to access. This issue is patched in version 3.8.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Vantage6 | Vantage6 | < 3.6.1 | — |
| Vantage6 | Vantage6 | >= 3.7.0, <= 3.7.3 | — |
| Vantage6 | Vantage6 | 3.8.0 | Rc1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-22738?
How severe is CVE-2023-22738?
How do I fix CVE-2023-22738?
Are you affected by CVE-2023-22738?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
