CVE-2024-22193

Insecure Storage of Sensitive Information in pypi/vantage6

Identifiers

GHSA-rjmv-52mp-gjrr, CVE-2024-22193

Package Slug

pypi/vantage6

Vulnerability

Insecure Storage of Sensitive Information

Description

The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). There are no checks on whether the input is encrypted if a task is created in an encrypted collaboration. Therefore, a user may accidentally create a task with sensitive input data that will then be stored unencrypted in a database. Users should ensure they set the encryption setting correctly. This vulnerability is patched in 4.2.0.

Affected Versions

All versions before 4.2.0

Solution

Upgrade to version 4.2.0 or above.

Last Modified

2024-01-31

source