CVE-2023-22738Medium· 6.5▾ Sunlitvantage6 vulnerable to Improper Preservation of Permissions
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
Assigning existing users to a different organization is currently possible. It may lead to unintended access: if a user from organization A is accidentally assigned to organization B, they will retain their permissions and therefore might be able to access stuff they should not be allowed to access.
Update to 3.8.0
None
None
If you have any questions or comments about this advisory:
vantage6 < 3.8.0Upgrade to a patched release:
vantage6 3.8.0Connected by shared product, vendor, weakness, or advisory.
CVE-2024-21649High· 8.8vantage6 remote code execution vulnerability
CVE-2024-22193Low· 3.5vantage6 may create unencrypted tasks in encrypted collaboration
CVE-2023-41881Low· 3.7vantage6 does not properly delete linked resources when deleting a collaboration
CVE-2023-23930High· 7.2Pickle serialization vulnerable to Deserialization of Untrusted Data
CVE-2023-23929High· 8.8vantage6 refresh tokens do not expire
CVE-2026-73652Highvantage6 is an open-source infrastructure for privacy preserving analysis