CVE-2024-23823: CORS settings overly permissive in vantage6
Impact The vantage6 server has no restrictions on CORS settings. It should be possible for people to set the allowed origins of the server.
The impact is limited because v6 does not use session cookies
Patches No
Workarounds No
Other sources
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. The vantage6 server has no restrictions on CORS settings. It should be possible for people to set the allowed origins of the server. The impact is limited because v6 does not use session cookies. This issue has been addressed in commit 70bb4e1d8 and is expected to ship in subsequent releases. Users are advised to upgrade as soon as a new release is available. There are no known workarounds for this vulnerability.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23823?
The severity of CVE-2024-23823 is not specified, but it is considered a security concern due to unrestricted CORS settings.
How do I fix CVE-2024-23823?
Currently, there are no patches available to fix CVE-2024-23823.
Which versions of the software are affected by CVE-2024-23823?
CVE-2024-23823 affects versions of the vantage6 package from 4.2.2 and below.
What are the potential risks of CVE-2024-23823?
CVE-2024-23823 presents risks related to CORS misconfigurations which could lead to unauthorized access.
Are there any workarounds for CVE-2024-23823?
No, there are no provided workarounds for mitigating CVE-2024-23823.