vantage6 may create unencrypted tasks in encrypted collaboration
Description
Published by the National Vulnerability Database
Jan 30, 2024
Published to the GitHub Advisory Database
Jan 30, 2024
Reviewed
Jan 30, 2024
Last updated
Feb 8, 2024
Impact
There are no checks on whether the input is encrypted if a task is created in an encrypted collaboration. Therefore, a user may accidentally create a task with sensitive input data that will then be stored unencrypted in a database.
Workarounds
This is not an issue with the normal workflow, only if e.g. a user with the python client sets encryption to the wrong value.
References