GHSA-vvjv-97j8-94xh · Severity: high · Ecosystem: pip — vantage6 vulnerable to Improper Preservation of Permissions
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Assigning existing users to a different organizations is currently possible. It may lead to unintended access: if a user from organization A is accidentally assigned to organization B, they will retain their permissions and therefore might be able to access stuff they should not be allowed to access. This issue is patched in version 3.8.0.
Conclusion & alert: CVE-2023-22738 is rated Low Risk (35.6/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.38%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.20% | 0.38% | +0.18% |
| 2 | 2026-03-02 | 0.05% | 0.20% | +0.14% |
| 3 | 2024-01-30 | — | 0.05% | — |
Full EPSS history (5 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.3 | 3.1 | MEDIUM |
|
2.1 | 4.2 | [email protected] |
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
GHSA-vvjv-97j8-94xh · Severity: high · Ecosystem: pip — vantage6 vulnerable to Improper Preservation of Permissions
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| vantage6 | vantage6 | < 3.6.1 | cpe:2.3:a:vantage6:vantage6:*:*:*:*:*:*:*:* |
| vantage6 | vantage6 | >= 3.7.0, <= 3.7.3 | cpe:2.3:a:vantage6:vantage6:*:*:*:*:*:*:*:* |
| vantage6 | vantage6 | 3.8.0 | cpe:2.3:a:vantage6:vantage6:3.8.0:rc1:*:*:*:*:*:* |
| vantage6 | vantage6 | 3.8.0 | cpe:2.3:a:vantage6:vantage6:3.8.0:rc2:*:*:*:*:*:* |
| vantage6 | vantage6 | 3.8.0 | cpe:2.3:a:vantage6:vantage6:3.8.0:rc3:*:*:*:*:*:* |