ZeroHour

CVE-2024-6299

CVSS 3.1
3.7 low
EPSS
<1%p6
Published
()
Modified
Description

Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an expired key to forge requests as the remote server, as well as PDUs with timestamps past the expiry date

Vendors
conduit
Products
conduit
Weakness
CWE-324
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.