CVE-2023-23929: VANTAGE6

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh token is valid indefinitely. The refresh token should get a validity of 24-48 hours. A fix was released in version 3.8.0.

Affected products

  • VANTAGE6 VANTAGE6: before 3.8.0 (fixed in 3.8.0)

Published 2023-03-04. Last modified 2026-06-17.