Description
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). There are no checks on whether the input is encrypted if a task is created in an encrypted collaboration. Therefore, a user may accidentally create a task with sensitive input data that will then be stored unencrypted in a database. Users should ensure they set the encryption setting correctly. This vulnerability is patched in 4.2.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0171 | The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). There are no checks on whether the input is encrypted if a task is created in an encrypted collaboration. Therefore, a user may accidentally create a task with sensitive input data that will then be stored unencrypted in a database. Users should ensure they set the encryption setting correctly. This vulnerability is patched in 4.2.0. |
Github GHSA |
GHSA-rjmv-52mp-gjrr | vantage6 may create unencrypted tasks in encrypted collaboration |
References
History
Tue, 17 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-17T13:44:50.458Z
Reserved: 2024-01-08T04:59:27.370Z
Link: CVE-2024-22193
Updated: 2024-08-01T22:35:34.957Z
Status : Modified
Published: 2024-01-30T16:15:48.310
Modified: 2024-11-21T08:55:46.063
Link: CVE-2024-22193
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA