Home

Description

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access to an authenticated session, they can try to brute-force the user password by using the change password functionality: they can call that route infinitely which will return the message that password is wrong until it is correct. This vulnerability is fixed in 4.11.

PUBLISHED Reserved 2025-04-17 | Published 2025-06-12 | Updated 2025-06-12 | Assigner GitHub_M




LOW: 1.7CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U

Problem types

CWE-307: Improper Restriction of Excessive Authentication Attempts

Product status

< 4.11.0
affected

References

github.com/...ntage6/security/advisories/GHSA-j6g5-p62x-58hw

cve.org (CVE-2025-43863)

nvd.nist.gov (CVE-2025-43863)

Download JSON