PT-2024-37525 · Conduit · Conduit

CVE-2024-6303

·

Published

2024-06-25

·

Updated

2024-09-20

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Conduit versions prior to 0.7.0
Description: The issue concerns missing authorization in the Client-Server API, allowing for unauthorized removal and addition of aliases to different rooms. This can be exploited for privilege escalation by moving the #admins alias to a controlled room, enabling the execution of commands such as resetting passwords, signing JSON with the server's key, deactivating users, and more.
Recommendations: For Conduit versions prior to 0.7.0, update to version 0.7.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Client-Server API to minimize the risk of exploitation. Avoid using the API for sensitive operations until the issue is resolved.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6303

Affected Products

Conduit