Description
Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an expired key to forge requests as the remote server, as well as PDUs with timestamps past the expiry date
No analysis available yet.
Remediation
Vendor Solution
Upgrade to version 0.8.0
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47416 | Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an expired key to forge requests as the remote server, as well as PDUs with timestamps past the expiry date |
References
History
Fri, 20 Sep 2024 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Conduit
Conduit conduit |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:conduit:conduit:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Conduit
Conduit conduit |
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-08-29T15:04:59.770Z
Reserved: 2024-06-25T10:30:35.803Z
Link: CVE-2024-6299
Updated: 2024-08-01T21:33:05.377Z
Status : Modified
Published: 2024-06-25T13:15:50.587
Modified: 2024-11-21T09:49:23.313
Link: CVE-2024-6299
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD