CVE-2023-47631High· 7.2▾ Twilightvantage6-server node accepts non-whitelisted algorithms from malicious server
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
A node does not check if an image is allowed to run if a parent_id is set. A malicious party that breaches the server may modify it to set a fake parent_id and send a task of a non-whitelisted algorithm. The node will then execute it because the parent_id that is set prevents checks from being run. Relevant node code here
This impacts all servers that are breached by an expert user
Fixed in v4.1.2
None
vantage6-server < 4.1.2vantage6-node < 4.1.2Upgrade to a patched release:
vantage6-server 4.1.2vantage6-node 4.1.2Connected by shared product, vendor, weakness, or advisory.