ZeroHour

CVE-2024-6301

CVSS 3.1
7.5 high
EPSS
<1%p6
Published
()
Modified
Description

Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs

Vendors
conduit
Products
conduit
Weakness
CWE-346
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.