Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs
History

Fri, 20 Sep 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Conduit
Conduit conduit
CPEs cpe:2.3:a:conduit:conduit:*:*:*:*:*:*:*:*
Vendors & Products Conduit
Conduit conduit

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2024-06-25T13:02:20.904Z

Updated: 2024-08-29T15:04:59.937Z

Reserved: 2024-06-25T10:30:45.683Z

Link: CVE-2024-6301

cve-icon Vulnrichment

Updated: 2024-08-01T21:33:05.348Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-25T13:15:51.077

Modified: 2024-09-20T18:58:43.323

Link: CVE-2024-6301

cve-icon Redhat

No data.