QID 995941
Date Published: 2023-11-16
QID 995941: Python (Pip) Security Update for vantage6-server (GHSA-vc3v-ppc7-v486)
A node does not check if an image is allowed to run if a parent_id is set. A malicious party that breaches the server may modify it to set a fake parent_id and send a task of a non-whitelisted algorithm. The node will then execute it because the parent_id that is set prevents checks from being run. Relevant node code here
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-vc3v-ppc7-v486 for updates and patch information.
Vendor References
- GHSA-vc3v-ppc7-v486 -
github.com/advisories/GHSA-vc3v-ppc7-v486
CVEs related to QID 995941
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vc3v-ppc7-v486 | vantage6-server |
|