Skip to main content

Vendor archive

conduit CVEs

Beta · best-effort

5 CVEs tagged to vendor conduit1 Critical, 1 High, 2 Medium, 1 Low, 0 Unrated.

CVE-2024-6303

Published Jun 25, 2024

Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for privilege escalation by moving…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-6302

Published Jun 25, 2024

Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower, allowing a local user to redact any message from users on the same server, given that…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6301

Published Jun 25, 2024

Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6300

Published Jun 25, 2024

Incomplete cleanup when performing redactions in Conduit, allowing an attacker to check whether certain strings were present in the PDU before redaction

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-6299

Published Jun 25, 2024

Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an expired key to forge requests as the remote server, as wel…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1