PYSEC-2023-313

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/vantage6/PYSEC-2023-313.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2023-313
Aliases
Withdrawn
2026-07-09T16:23:00Z
Published
2023-03-01T17:15:10.980Z
Modified
2026-07-09T16:45:10.230380936Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L CVSS Calculator
Summary
[none]
Details

Withdrawn as duplicate of PYSEC-2023-52 vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user of wrong username/password combination if the username actually exists. This is an attempt to prevent bots from obtaining usernames. However, if a wrong password is entered a number of times, the user account is blocked temporarily. This issue has been fixed in version 3.8.0.

References

Affected packages

PyPI / vantage6

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.3.3
Fixed
3.8.0

Affected versions

3.*
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7a2
3.3.7a3
3.3.7
3.3.8a1
3.3.8a2
3.3.8a4
3.3.8a5
3.3.8a6
3.3.8a7
3.3.8a8
3.4.0a1
3.4.0a2
3.4.0a3
3.4.0a6
3.4.0
3.4.1a0
3.4.1a1
3.4.1a2
3.4.1a3
3.4.1
3.4.2a0
3.4.2
3.4.3
3.5.0rc1
3.5.0rc2
3.5.0rc3
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1rc1
3.6.1rc2
3.6.1rc3
3.6.1
3.7.0rc1
3.7.0rc2
3.7.0
3.7.1
3.7.2
3.7.3
3.8.0rc3

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/vantage6/PYSEC-2023-313.yaml"