PT-2024-37525 · Conduit · Conduit
Published
2024-06-25
·
Updated
2024-09-20
·
CVE-2024-6303
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Conduit versions prior to 0.7.0
Description:
The issue concerns missing authorization in the Client-Server API, allowing for unauthorized removal and addition of aliases to different rooms. This can be exploited for privilege escalation by moving the #admins alias to a controlled room, enabling the execution of commands such as resetting passwords, signing JSON with the server's key, deactivating users, and more.
Recommendations:
For Conduit versions prior to 0.7.0, update to version 0.7.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Client-Server API to minimize the risk of exploitation. Avoid using the API for sensitive operations until the issue is resolved.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Conduit