GHSA-vc3v-ppc7-v486
HIGHCVE-2023-47631A node does not check if an image is allowed to run if a parentid is set. A malicious party that breaches the server may modify it to set a fake parentid and send a task of a non-whitelisted algorithm. The node will then execute it because the parentid that is set prevents checks from being run. Relevant node code [here](https://github.com/vantage6/vantage6/blob/version/4.1.1/vantage6-node/vantage
- Affected
- < 4.1.2
- Fixed in
- 4.1.2
- Weakness
- CWE-345
- Published
- 2023-11-14
- Source
- github