The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Prior to 4.2.0, authenticated users could inject code into algorithm environment variables, resulting in remote code execution. This vulnerability is patched in 4.2.0.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0169 | The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Prior to 4.2.0, authenticated users could inject code into algorithm environment variables, resulting in remote code execution. This vulnerability is patched in 4.2.0. |
Github GHSA |
GHSA-w9h2-px87-74vx | vantage6 remote code execution vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 29 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-29T15:05:10.990Z
Reserved: 2023-12-29T16:10:20.366Z
Link: CVE-2024-21649
Updated: 2024-08-01T22:27:35.818Z
Status : Modified
Published: 2024-01-30T16:15:47.653
Modified: 2024-11-21T08:54:48.030
Link: CVE-2024-21649
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA