vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. Much like GHSA-45gq-q4xh-cp53, it is possible to find which usernames exist in vantage6 by calling the API routes `/recover/lost` and `/2fa/lost`. These routes send emails to users if they have lost their password or MFA token. This issue has been addressed in commit `aecfd6d0e` and is expected to ship in subsequent releases. Users are advised to upgrade as soon as a new release is available. There are no known workarounds for this vulnerability.

Subscriptions

Vendors Products
Vantage6 Subscribe
Vantage6 Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-0829 vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. Much like GHSA-45gq-q4xh-cp53, it is possible to find which usernames exist in vantage6 by calling the API routes `/recover/lost` and `/2fa/lost`. These routes send emails to users if they have lost their password or MFA token. This issue has been addressed in commit `aecfd6d0e` and is expected to ship in subsequent releases. Users are advised to upgrade as soon as a new release is available. There are no known workarounds for this vulnerability.
Github GHSA Github GHSA GHSA-5h3x-6gwf-73jm vantage6 vulnerable to a username timing attack on recover password/MFA token
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 30 Jul 2025 20:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:vantage6:vantage6:*:*:*:*:*:*:*:*

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-26T15:21:53.399Z

Reserved: 2024-01-29T20:51:26.013Z

Link: CVE-2024-24770

cve-icon Vulnrichment

Updated: 2024-08-01T23:28:12.459Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-14T19:15:49.973

Modified: 2025-07-30T20:32:42.360

Link: CVE-2024-24770

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:45:22Z

Weaknesses