
CVE-2024-24562 – Security headers not set in vantage6-UI
https://notcve.org/view.php?id=CVE-2024-24562
14 Mar 2024 — vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers are not set. This issue has been addressed in commit `68dfa6614` which is expected to be included in future releases. Users are advised to upgrade when a new release is made. While an upgrade path is not available users may modify the docker image build to insert the headers into nginx. vantage6-UI es la interfaz de usuario oficial para el servidor vantage6. • https://github.com/vantage6/vantage6-UI/commit/68dfa661415182da0e5717bd58db3d00aedcbd2e • CWE-668: Exposure of Resource to Wrong Sphere CWE-693: Protection Mechanism Failure •

CVE-2024-22200 – vantage6-UI docker image leaks software version information
https://notcve.org/view.php?id=CVE-2024-22200
30 Jan 2024 — vantage6-UI is the User Interface for vantage6. The docker image used to run the UI leaks the nginx version. To mitigate the vulnerability, users can run the UI as an angular application. This vulnerability was patched in 4.2.0. vantage6-UI es la interfaz de usuario de vantage6. La imagen de la ventana acoplable utilizada para ejecutar la interfaz de usuario filtra la versión de nginx. • https://github.com/vantage6/vantage6-UI/commit/92e0fb5102b544d5bcc23980d973573733e2e020 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •