Skip to main content

Vendor archive

vantage6 CVEs

Beta · best-effort

18 CVEs tagged to vendor vantage60 Critical, 3 High, 9 Medium, 6 Low, 0 Unrated.

CVE-2025-43866

Published Jun 12, 2025

vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The auto-generat…

CVSS 1.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-43863

Published Jun 12, 2025

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access…

CVSS 1.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-24770

Published Mar 14, 2024

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. Much like GHSA-45gq-q4x…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24562

Published Mar 14, 2024

vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers are not set. This issue has been addressed in commit `68dfa66…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23823

Published Mar 14, 2024

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. The vantage6 server has…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22200

Published Jan 30, 2024

vantage6-UI is the User Interface for vantage6. The docker image used to run the UI leaks the nginx version. To mitigate the vulnerability, users can run the UI as an angular appl…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-22193

Published Jan 30, 2024

The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). There are no checks on whether…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-21671

Published Jan 30, 2024

The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). It is possible to find out use…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-21653

Published Jan 30, 2024

The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Nodes and servers get a ssh co…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21649

Published Jan 30, 2024

The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Prior to 4.2.0, authenticated u…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47631

Published Nov 14, 2023

vantage6 is a framework to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). In affected versions a node does not ch…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41882

Published Oct 11, 2023

vantage6 is privacy preserving federated learning infrastructure. The endpoint /api/collaboration/{id}/task is used to collect all tasks from a certain collaboration. To get such…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41881

Published Oct 11, 2023

vantage6 is privacy preserving federated learning infrastructure. When a collaboration is deleted, the linked resources (such as tasks from that collaboration) should be deleted.…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-28635

Published Oct 11, 2023

vantage6 is privacy preserving federated learning infrastructure. Prior to version 4.0.0, malicious users may try to get access to resources they are not allowed to see, by creati…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23930

Published Oct 11, 2023

vantage6 is privacy preserving federated learning infrastructure. Versions prior to 4.0.0 use pickle, which has known security issue, as a default serialization module but that ha…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23929

Published Mar 4, 2023

vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh token is valid indefinitely. The refresh token should get a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22738

Published Mar 1, 2023

vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Assigning existing users to a different organizations is currently possible. It may…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39228

Published Mar 1, 2023

vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user of wrong username/password combination if the use…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1