PT-2024-37524 · Conduit · Conduit

Published

2024-06-25

·

Updated

2024-09-20

·

CVE-2024-6302

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Conduit versions v0.6.0 and lower
Description: The issue is related to a lack of privilege checking when processing a redaction, allowing a local user to redact any message from users on the same server if they can send redaction events.
Recommendations: For Conduit versions v0.6.0 and lower, consider restricting access to redaction events to prevent unauthorized message redaction until a patch is available.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-6302

Affected Products

Conduit