Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for privilege escalation by moving the #admins alias to a room which they control, allowing them to run commands resetting passwords, siging json with the server's key, deactivating users, and more
Advisories
Source ID Title
EUVD EUVD EUVD-2024-47420 Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for privilege escalation by moving the #admins alias to a room which they control, allowing them to run commands resetting passwords, siging json with the server's key, deactivating users, and more
Fixes

Solution

Upgrade to version 0.8.0


Workaround

No workaround given by the vendor.

History

Fri, 20 Sep 2024 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Conduit
Conduit conduit
CPEs cpe:2.3:a:conduit:conduit:*:*:*:*:*:*:*:*
Vendors & Products Conduit
Conduit conduit

Thu, 29 Aug 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2024-08-29T15:05:00.177Z

Reserved: 2024-06-25T10:30:55.673Z

Link: CVE-2024-6303

cve-icon Vulnrichment

Updated: 2024-08-01T21:33:05.446Z

cve-icon NVD

Status : Modified

Published: 2024-06-25T13:15:51.550

Modified: 2024-11-21T09:49:23.837

Link: CVE-2024-6303

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.