Junglewise Threat Intelligence

CVE-2023-23929: PYSEC-2023-54 - vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh token is valid indefi

CVE-2023-23929 · Severity: low · CVSS 3.1 · Published 2023-03-04

Technologies: vantage6 (PyPI). Vendors: PyPI.

Executive brief

vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh token is valid indefinitely. The refresh token should get a validity of 24-48 hours. A fix was released in version 3.8.0.

Affected products

  • PyPI vantage6

Related threats