Description
Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for privilege escalation by moving the #admins alias to a room which they control, allowing them to run commands resetting passwords, siging json with the server's key, deactivating users, and more
No analysis available yet.
Remediation
Vendor Solution
Upgrade to version 0.8.0
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47420 | Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for privilege escalation by moving the #admins alias to a room which they control, allowing them to run commands resetting passwords, siging json with the server's key, deactivating users, and more |
References
History
Fri, 20 Sep 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Conduit
Conduit conduit |
|
| CPEs | cpe:2.3:a:conduit:conduit:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Conduit
Conduit conduit |
Thu, 29 Aug 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-08-29T15:05:00.177Z
Reserved: 2024-06-25T10:30:55.673Z
Link: CVE-2024-6303
Updated: 2024-08-01T21:33:05.446Z
Status : Modified
Published: 2024-06-25T13:15:51.550
Modified: 2024-11-21T09:49:23.837
Link: CVE-2024-6303
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD