vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The auto-generated key is a UUID1, which is not cryptographically secure as it is predictable to some extent. This vulnerability is fixed in 4.11.0.
CVSS
No CVSS.
References
Configurations
No configuration.
History
12 Jun 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-12 18:15
Updated : 2025-06-12 18:15
NVD link : CVE-2025-43866
Mitre link : CVE-2025-43866
CVE.ORG link : CVE-2025-43866
JSON object : View
Products Affected
No product.
CWE
CWE-330
Use of Insufficiently Random Values