CVE-2023-23929High· 8.8▾ Twilightvantage6 refresh tokens do not expire
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
From issue:
Problem description Currently, the refresh token is valid indefinitely. This is bad security practice.
Desired solution The refresh token should get a validity of 24-48 hours.
Additional context
When implementing this, also check that the refresh token returns a new refresh token When implementing this, also adapt the UI so that it logs out if refresh token is no longer valid. When implementing this, ensure that nodes refresh their token periodically so that they do not have to be restarted manually.
None available
None available
vantage6 < 3.8.0Upgrade to a patched release:
vantage6 3.8.0Connected by shared product, vendor, weakness, or advisory.
CVE-2024-21649High· 8.8vantage6 remote code execution vulnerability
CVE-2023-22738Medium· 6.5vantage6 vulnerable to Improper Preservation of Permissions
CVE-2024-22193Low· 3.5vantage6 may create unencrypted tasks in encrypted collaboration
CVE-2023-41881Low· 3.7vantage6 does not properly delete linked resources when deleting a collaboration
CVE-2023-23930High· 7.2Pickle serialization vulnerable to Deserialization of Untrusted Data
CVE-2026-73652Highvantage6 is an open-source infrastructure for privacy preserving analysis