Business information leak In vantage6
Description
vantage6 may create unencrypted tasks in encrypted collaboration
Impact
There are no checks on whether the input is encrypted if a task is created in an encrypted collaboration. Therefore, a user may accidentally create a task with sensitive input data that will then be stored unencrypted in a database.
Workarounds
This is not an issue with the normal workflow, only if e.g. a user with the python client sets encryption to the wrong value.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 4.2.0 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.