PT-2024-37524 · Conduit · Conduit
Published
2024-06-25
·
Updated
2024-09-20
·
CVE-2024-6302
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Conduit versions v0.6.0 and lower
Description:
The issue is related to a lack of privilege checking when processing a redaction, allowing a local user to redact any message from users on the same server if they can send redaction events.
Recommendations:
For Conduit versions v0.6.0 and lower, consider restricting access to redaction events to prevent unauthorized message redaction until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Conduit