vantage6@3.3.2 vulnerabilities
vantage6 command line interface
-
latest version
4.8.1
-
latest non vulnerable version
-
first published
5 years ago
-
latest version published
4 days ago
-
licenses detected
- [3.3.0a0,)
Direct Vulnerabilities
Known vulnerabilities in the vantage6 package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
vantage6 is a vantage6 command line interface Affected versions of this package are vulnerable to Improper Access Control in the collaboration management process. An attacker can extend their influence by adding extra organizations to their collaboration and creating new users with known passwords, allowing them to read task results of other collaborations. How to fix Improper Access Control? Upgrade |
[,4.5.0rc3)
|
vantage6 is a vantage6 command line interface Affected versions of this package are vulnerable to Race Condition via the API routes How to fix Race Condition? Upgrade |
[,4.3.0)
|
vantage6 is a vantage6 command line interface Affected versions of this package are vulnerable to Incorrect Authorization due to overly permissive CORS settings. An attacker can exploit this vulnerability by sending requests from unauthorized origins, potentially leading to unauthorized actions or data exposure. How to fix Incorrect Authorization? Upgrade |
[,4.3.0)
|
vantage6 is a vantage6 command line interface Affected versions of this package are vulnerable to Insecure Storage of Sensitive Information due to insufficient validation of encryption settings when creating tasks in an encrypted collaboration. An attacker can inadvertently store sensitive input data unencrypted in the database by creating a task without the proper encryption setting. How to fix Insecure Storage of Sensitive Information? Upgrade |
[,4.2.0)
|
vantage6 is a vantage6 command line interface Affected versions of this package are vulnerable to Improper Access Control due to insecure default SSH configurations for node and server containers. An attacker can gain unauthorized root access with password authentication by exploiting this misconfiguration. Note: This is only exploitable if the SSH service is exposed, which is not the case in a proper deployment. How to fix Improper Access Control? Upgrade |
[,4.2.0)
|
vantage6 is a vantage6 command line interface Affected versions of this package are vulnerable to Arbitrary Code Injection due to improper handling of algorithm environment variables. An attacker can execute arbitrary code by injecting malicious input into these variables. How to fix Arbitrary Code Injection? Upgrade |
[,4.2.0)
|
vantage6 is a vantage6 command line interface Affected versions of this package are vulnerable to Deserialization of Untrusted Data through the How to fix Deserialization of Untrusted Data? Upgrade |
[,4.0.2)
|
vantage6 is a vantage6 command line interface Affected versions of this package are vulnerable to Exposure of Sensitive Information to an Unauthorized Actor when a collaboration is deleted, the linked resources such as tasks from that collaboration should also be deleted. An attacker can potentially see results of the deleted collaboration in some cases by creating a new collaboration with the same id as the deleted one. This is only exploitable if a new collaboration is created with the same id as a previously deleted collaboration. How to fix Exposure of Sensitive Information to an Unauthorized Actor? Upgrade |
[,4.0.0)
|
vantage6 is a vantage6 command line interface Affected versions of this package are vulnerable to Incorrect Authorization through the How to fix Incorrect Authorization? Upgrade |
[,4.0.0)
|
vantage6 is a vantage6 command line interface Affected versions of this package are vulnerable to Incorrect Authorization when the How to fix Incorrect Authorization? Upgrade |
[,4.0.0)
|
vantage6 is a vantage6 command line interface Affected versions of this package are vulnerable to Insufficient Session Expiration due to missing maximum length of refresh tokens. How to fix Insufficient Session Expiration? Upgrade |
[,3.8.0rc3)
|
vantage6 is a vantage6 command line interface Affected versions of this package are vulnerable to Improper Preservation of Permissions such that assigning existing users to a different organization is possible, which may lead to unintended access. If a user from organization How to fix Improper Preservation of Permissions? Upgrade |
[,3.8.0rc3)
|
vantage6 is a vantage6 command line interface Affected versions of this package are vulnerable to Information Exposure such that, if a wrong password is entered several times, the user account is blocked temporarily. This way an attacker can find out which usernames are valid. How to fix Information Exposure? Upgrade |
[,3.8.0rc3)
|