Vulnerability Details CVE-2024-6302
Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower, allowing a local user to redact any message from users on the same server, given that they are able to send redaction events.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 14.3%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2024-6302
-
cpe:2.3:a:conduit:conduit:-
-
cpe:2.3:a:conduit:conduit:0.0.0
-
cpe:2.3:a:conduit:conduit:0.2.0
-
cpe:2.3:a:conduit:conduit:0.3.0
-
cpe:2.3:a:conduit:conduit:0.4.0
-
cpe:2.3:a:conduit:conduit:0.5.0
-
cpe:2.3:a:conduit:conduit:0.6.0