Description
Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower, allowing a local user to redact any message from users on the same server, given that they are able to send redaction events.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to 0.7.0 or later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47419 | Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower, allowing a local user to redact any message from users on the same server, given that they are able to send redaction events. |
References
History
Fri, 20 Sep 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Conduit
Conduit conduit |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:conduit:conduit:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Conduit
Conduit conduit |
Wed, 18 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-09-17T18:00:30.094Z
Reserved: 2024-06-25T10:30:50.678Z
Link: CVE-2024-6302
Updated: 2024-08-01T21:33:05.339Z
Status : Modified
Published: 2024-06-25T13:15:51.313
Modified: 2024-11-21T09:49:23.700
Link: CVE-2024-6302
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD