HIGH
Origin Validation Error in Conduit
Published Jun 25, 2024
7.5
HIGHCVSS 3.1
EPSS 0.17%
Description
Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs
Affected products
-
- Version 0StatusaffectedConstraints<0.8.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The Conduit Contributors | Conduit | unaffected |
|
-
- Version 0StatusaffectedConstraints<0.8.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The Conduit Contributors | Conduit | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to version 0.8.0
Weaknesses (1)
References (3)
- https://conduit.rs/changelog/#v0-8-0-2024-06-12 Release Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-47418 Advisory
- https://gitlab.com/famedly/conduit/-/releases/v0.8.0 Release Notes
| Link | Providers | Tags |
|---|---|---|
| https://conduit.rs/changelog/#v0-8-0-2024-06-12 | Release Notes | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-47418 | Advisory | |
| https://gitlab.com/famedly/conduit/-/releases/v0.8.0 | Release Notes |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Jun 25, 2024
Updated Aug 29, 2024
Reserved Jun 25, 2024
Link CVE-2024-6301
CISA Vulnrichment
Updated Jun 25, 2024
ENISA EUVD
EUVD-2024-47418 Assigner GitLab
Published Jun 25, 2024
Updated Aug 29, 2024
Exploited since n/a
Link EUVD-2024-47418