{"id":"CVE-2023-41881","aliases":["GHSA-rf54-7qrr-96j6","PYSEC-2023-200"],"url":"https://o3.security/vulnerability/CVE-2023-41881","summary":"Deleting a collaboration should also delete linked resources","details":"vantage6 is privacy preserving federated learning infrastructure. When a collaboration is deleted, the linked resources (such as tasks from that collaboration) should be deleted. This is partly to manage data properly, but also to prevent a potential (but unlikely) side-effect that affects versions prior to 4.0.0, where if a collaboration with id=10 is deleted, and subsequently a new collaboration is created with id=10, the authenticated users in that collaboration could potentially see results of the deleted collaboration in some cases. Version 4.0.0 contains a patch for this issue. There are no known workarounds.","published":"2023-10-11T19:30:43.808Z","modified":"2026-08-12T03:51:25.151546616Z","cvss":{"score":3.7,"severity":"LOW","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"vantage6","fixedVersion":"4.0.0"}],"fix":{"url":"https://github.com/vantage6/vantage6/pull/748","label":"vantage6/vantage6#748"},"references":[{"type":"WEB","url":"https://github.com/vantage6/vantage6/blob/0682c4288f43fee5bcc72dc448cdd99bd7e57f76/docs/release_notes.rst#400"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/41xxx/CVE-2023-41881.json"},{"type":"ADVISORY","url":"https://github.com/vantage6/vantage6/security/advisories/GHSA-rf54-7qrr-96j6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-41881"},{"type":"FIX","url":"https://github.com/vantage6/vantage6/pull/748"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:25.151546616Z"}}