Safety vulnerability ID: 54409
The information on this page was manually curated by our Cybersecurity Intelligence Team.
NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pickle and no safe deserialization. The deserialization of Untrusted Data may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity.
Latest version: 2.5.2
Federated Learning Application Runtime Environment
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application