HIGH
vantage6's Pickle serialization is insecure
Published Oct 11, 2023
8.6
HIGHCVSS 4.0
EPSS 0.89%
Description
vantage6 is privacy preserving federated learning infrastructure. Versions prior to 4.0.0 use pickle, which has known security issue, as a default serialization module but that has known security issues. All users of vantage6 that post tasks with the default serialization are affected. Version 4.0.0 contains a patch. Users may specify JSON serialization as a workaround.
Affected products
-
- Version < 4.0.0StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://github.com/advisories/GHSA-5m22-cfq9-86x6 Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/vantage6/PYSEC-2023-196.yaml
- https://github.com/vantage6/vantage6/blob/0682c4288f43fee5bcc72dc448cdd99bd7e57f76/docs/release_notes.rst#400 x_refsource_MISCRelease Notes
- https://github.com/vantage6/vantage6/commit/e62f03bacf2247bd59eed217e2e7338c3a01a5f0 x_refsource_MISCPatch
- https://github.com/vantage6/vantage6/security/advisories/GHSA-5m22-cfq9-86x6 x_refsource_CONFIRMVendor Advisory
- https://medium.com/ochrona/python-pickle-is-notoriously-insecure-d6651f1974c9 x_refsource_MISCExploitPermissions RequiredTechnical DescriptionThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-23930
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-5m22-cfq9-86x6 | Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/vantage6/PYSEC-2023-196.yaml | ||
| https://github.com/vantage6/vantage6/blob/0682c4288f43fee5bcc72dc448cdd99bd7e57f76/docs/release_notes.rst#400 | x_refsource_MISCRelease Notes | |
| https://github.com/vantage6/vantage6/commit/e62f03bacf2247bd59eed217e2e7338c3a01a5f0 | x_refsource_MISCPatch | |
| https://github.com/vantage6/vantage6/security/advisories/GHSA-5m22-cfq9-86x6 | x_refsource_CONFIRMVendor Advisory | |
| https://medium.com/ochrona/python-pickle-is-notoriously-insecure-d6651f1974c9 | x_refsource_MISCExploitPermissions RequiredTechnical DescriptionThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-23930 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Oct 11, 2023
Updated Sep 18, 2024
Reserved Jan 19, 2023
Link CVE-2023-23930
CISA Vulnrichment
GHSA-5M22-CFQ9-86X6 Updated Sep 18, 2024