vantage6 may create unencrypted tasks in encrypted collaboration
Description
        Published by the National Vulnerability Database
      Jan 30, 2024 
    
  
        Published to the GitHub Advisory Database
      Jan 30, 2024 
    
  
        Reviewed
      Jan 30, 2024 
    
  
        Last updated
      Feb 8, 2024 
    
  
Impact
There are no checks on whether the input is encrypted if a task is created in an encrypted collaboration. Therefore, a user may accidentally create a task with sensitive input data that will then be stored unencrypted in a database.
Workarounds
This is not an issue with the normal workflow, only if e.g. a user with the python client sets encryption to the wrong value.
References