Required CVE Record Information
Description
Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower, allowing a local user to redact any message from users on the same server, given that they are able to send redaction events.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
8.1 | HIGH | 3.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Credits
- Timo Kösters for finding the vulnerability, Matthias Ahouansou for patching it finder
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- https://gitlab.com/famedly/conduit/-/releases/v0.7.0 x_transferred
- https://conduit.rs/changelog/#v0-7-0-2024-04-25 x_transferred