Home/Product/vantage6
Product

vantage6

18 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-43866
< 4.11.0
vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is auto-gener
7.5HIGH
CVE-2025-43863
< 4.11.0
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and
9.8CRITICAL
CVE-2024-24770
<= 4.2.2
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and
5.3MEDIUM
CVE-2024-24562
<= 4.2.0
vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers are not set.
5.4MEDIUM
CVE-2024-23823
< 4.2.1
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and
4.2MEDIUM
CVE-2024-22200
< 4.2.0
vantage6-UI is the User Interface for vantage6. The docker image used to run the UI leaks the nginx version. To mitigate the vulne
3.3LOW
CVE-2024-22193
< 4.2.0
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party C
3.5LOW
CVE-2024-21671
< 4.2.0
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party C
3.7LOW
CVE-2024-21653
< 4.2.0
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party C
6.5MEDIUM
CVE-2024-21649
< 4.2.0
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party C
8.8HIGH
CVE-2023-47631
< 4.1.2
vantage6 is a framework to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computati
7.2HIGH
CVE-2023-41882
< 4.0.0
vantage6 is privacy preserving federated learning infrastructure. The endpoint /api/collaboration/{id}/task is used to collect all
5.4MEDIUM
CVE-2023-41881
< 4.0.0
vantage6 is privacy preserving federated learning infrastructure. When a collaboration is deleted, the linked resources (such as t
3.7LOW
CVE-2023-28635
< 4.0.0
vantage6 is privacy preserving federated learning infrastructure. Prior to version 4.0.0, malicious users may try to get access to
5.4MEDIUM
CVE-2023-23930
< 4.0.2
vantage6 is privacy preserving federated learning infrastructure. Versions prior to 4.0.0 use pickle, which has known security iss
5.5MEDIUM
CVE-2023-23929
< 3.8.0
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh token is va
8.8HIGH
CVE-2023-22738
< 3.6.1
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Assigning existing users to a diff
6.3MEDIUM
CVE-2022-39228
>= 3.3.3 and < 3.8.0
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user
5.3MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin