Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower, allowing a local user to redact any message from users on the same server, given that they are able to send redaction events.

CVSS 1 Total

ScoreSeverityVersionVector String
8.1HIGH3.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Product Status

Learn more

Versions 1 Total

Default Status: unaffected

affected

Credits

  • Timo Kösters for finding the vulnerability, Matthias Ahouansou for patching it finder

Updated:

This container includes required additional information provided by the CVE Program for this vulnerability.

Authorized Data Publishers