HIGH
Refresh tokens do not expire in Vantage6
Published Mar 3, 2023
8.7
HIGHCVSS 4.0
EPSS 0.57%
Description
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh token is valid indefinitely. The refresh token should get a validity of 24-48 hours. A fix was released in version 3.8.0.
Affected products
-
- Version < 3.8.0StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/advisories/GHSA-4w59-c3gc-rrhp Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/vantage6/PYSEC-2023-54.yaml
- https://github.com/vantage6/vantage6/commit/48ebfca42359e9a6743e9598684585e2522cdce8 x_refsource_MISCPatch
- https://github.com/vantage6/vantage6/security/advisories/GHSA-4w59-c3gc-rrhp x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-23929
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-4w59-c3gc-rrhp | Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/vantage6/PYSEC-2023-54.yaml | ||
| https://github.com/vantage6/vantage6/commit/48ebfca42359e9a6743e9598684585e2522cdce8 | x_refsource_MISCPatch | |
| https://github.com/vantage6/vantage6/security/advisories/GHSA-4w59-c3gc-rrhp | x_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-23929 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Mar 3, 2023
Updated Feb 25, 2025
Reserved Jan 19, 2023
Link CVE-2023-23929
CISA Vulnrichment
GHSA-4W59-C3GC-RRHP Updated Feb 25, 2025