logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-23930

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-23930

Description:
vantage6 is privacy preserving federated learning infrastructure. Versions prior to 4.0.0 use pickle, which has known security issue, as a default serialization module but that has known security issues. All users of vantage6 that post tasks with the default serialization are affected. Version 4.0.0 contains a patch. Users may specify JSON serialization as a workaround.
Last updated date:
10/13/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
10/13/2023
Reference url to background

https://medium.com/ochrona/python-pickle-is-notoriously-insecure-d6651f1974c9

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy