CVE-2023-41881

Source
https://cve.org/CVERecord?id=CVE-2023-41881
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-41881.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-41881
Aliases
Published
2023-10-11T19:30:43.808Z
Modified
2026-04-10T05:01:22.118035Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Deleting a collaboration should also delete linked resources
Details

vantage6 is privacy preserving federated learning infrastructure. When a collaboration is deleted, the linked resources (such as tasks from that collaboration) should be deleted. This is partly to manage data properly, but also to prevent a potential (but unlikely) side-effect that affects versions prior to 4.0.0, where if a collaboration with id=10 is deleted, and subsequently a new collaboration is created with id=10, the authenticated users in that collaboration could potentially see results of the deleted collaboration in some cases. Version 4.0.0 contains a patch for this issue. There are no known workarounds.

Database specific
{
    "cwe_ids": [
        "CWE-200",
        "CWE-708"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/41xxx/CVE-2023-41881.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/vantage6/vantage6

Affected ranges

Type
GIT
Repo
https://github.com/vantage6/vantage6
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

version/0.*
version/0.0.0b3
version/3.*
version/3.3.0
version/3.3.0rc1
version/3.3.0rc2
version/3.3.0rc3
version/3.3.0rc4
version/3.3.1
version/3.3.2
version/3.3.3
version/3.3.4
version/3.3.5
version/3.3.6
version/4.*
version/4.0.0a1
version/4.0.0a10
version/4.0.0a2
version/4.0.0a3
version/4.0.0a4
version/4.0.0a5
version/4.0.0a6
version/4.0.0a7
version/4.0.0a8
version/4.0.0a9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-41881.json"