First published: Wed Mar 01 2023(Updated: )
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user of wrong username/password combination if the username actually exists. This is an attempt to prevent bots from obtaining usernames. However, if a wrong password is entered a number of times, the user account is blocked temporarily. This issue has been fixed in version 3.8.0.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vantage6 Vantage6 | >=3.3.3<3.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-39228 is a vulnerability in the vantage6 federated learning infrastructure that allows the wrong username/password combination to be checked without informing the user if the username actually exists.
CVE-2022-39228 has a severity level of medium with a score of 6.5.
CVE-2022-39228 affects vantage6 versions between 3.3.3 and 3.8.0.
To fix CVE-2022-39228, update vantage6 to a version beyond 3.8.0.
The CWEs associated with CVE-2022-39228 are CWE-203 and CWE-204.