VDB
EN
CRITICAL 9.8

PYSEC-2025-220

상세

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access to an authenticated session, they can try to brute-force the user password by using the change password functionality: they can call that route infinitely which will return the message that password is wrong until it is correct. This vulnerability is fixed in 4.11.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / vantage6
최초 영향 버전: 0 수정 버전: 4.11.0
수정 pip install --upgrade 'vantage6>=4.11.0'

참고