Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an expired key to forge requests as the remote server, as well as PDUs with timestamps past the expiry date
History

Fri, 20 Sep 2024 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Conduit
Conduit conduit
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:conduit:conduit:*:*:*:*:*:*:*:*
Vendors & Products Conduit
Conduit conduit

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2024-06-25T13:02:25.979Z

Updated: 2024-08-29T15:04:59.770Z

Reserved: 2024-06-25T10:30:35.803Z

Link: CVE-2024-6299

cve-icon Vulnrichment

Updated: 2024-08-01T21:33:05.377Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-25T13:15:50.587

Modified: 2024-09-20T19:24:13.170

Link: CVE-2024-6299

cve-icon Redhat

No data.