{"id":"CVE-2022-39228","aliases":["GHSA-36gx-9q6h-g429","PYSEC-2023-52"],"title":"vantage6 vulnerable to Observable Response Discrepancy","summary":"vantage6 vulnerable to Observable Response Discrepancy","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","vendor":"vantage6","product":"vantage6","ecosystem":"pip","affected":["vantage6 < 3.8.0"],"patched":["vantage6 3.8.0"],"published":"2023-02-28","updated":"2026-07-09","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-36gx-9q6h-g429","references":[{"url":"https://github.com/vantage6/vantage6/security/advisories/GHSA-36gx-9q6h-g429"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-39228"},{"url":"https://github.com/vantage6/vantage6/issues/59"},{"url":"https://github.com/vantage6/vantage6/pull/281"},{"url":"https://github.com/vantage6/vantage6/commit/ab4381c35d24add06f75d5a8a284321f7a340bd2"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/vantage6/PYSEC-2023-313.yaml"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/vantage6/PYSEC-2023-52.yaml"},{"url":"https://github.com/vantage6/vantage6"}],"tags":["osv","pip"],"epss":0.00596,"epssPercentile":0.47172,"ingestedAt":"2026-07-09T18:56:35.143Z","slug":"CVE-2022-39228","body":"## Overview\n\n### Impact\nWe are incorporating the password policies listed in https://github.com/vantage6/vantage6/issues/59. One measure is that we don't let the user know in case of wrong username/password combination if the username actually exists, to prevent that bots can guess usernames. However, if a wrong password is entered a number of times, the user account is blocked temporarily. This way you could still find out which usernames exist.\n\n### Patches\nUpdate to 3.8.0+\n\n### Workarounds\nNo\n\n### References\nhttps://github.com/vantage6/vantage6/issues/59\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [vantage6@iknl.nl](mailto:vantage6@iknl.nl)\n\n## Affected packages\n\n- `vantage6 < 3.8.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `vantage6 3.8.0`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}