vantage6 insecure SSH configuration for node and server containers
CVE-2024-21653
9.8CRITICAL
What is CVE-2024-21653?
The recent vulnerability in Vantage6 technology primarily concerns the SSH configuration that, by default, permits root login using password authentication. While optimal deployments do not expose the SSH service publicly, various configurations may inadvertently increase risk. Ensuring the integrity of sensitive operations such as Federated Learning and Multi-Party Computation necessitates more restrictive defaults. To mitigate this vulnerability effectively, it is recommended to adjust the deployment process by removing the SSH component from the Docker file and rebuilding the Docker image. Version 4.2.0 has been released which addresses this issue.
Affected Version(s)
vantage6 < 4.2.0
