Missing Authorization in Conduit
Vulnerability Description
Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for privilege escalation by moving the #admins alias to a room which they control, allowing them to run commands resetting passwords, siging json with the server's key, deactivating users, and more
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-6303
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Matthias Ahouansou for finding and patching the vulnerability
References
More from The Conduit Contributors
View All →Affected Vendor
The Conduit Contributors
View all reports →