Search
Find a vulnerability
Search criteria
2 vulnerabilities by the_conduit_contributors
CVE-2024-6301 (GCVE-0-2024-6301)
Vulnerability from nvd โ Published: 2024-06-25 13:02 โ Updated: 2024-08-29 15:04
VLAI
EPSS
VEX
Title
Origin Validation Error in Conduit
Summary
Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator ยท CISA-ADP (v2.0.3)
Decision recorded 2024-06-25 14:41 UTC
CWE
- CWE-346 - Origin Validation Error
Assigner
References
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| The Conduit Contributors | Conduit |
Affected:
0 , < 0.8.0
(semver)
|
|
| the_conduit_contributors | conduit |
Affected:
0 , < 0.8.0
(custom)
cpe:2.3:a:the_conduit_contributors:conduit:0.8.0:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:the_conduit_contributors:conduit:0.8.0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "conduit",
"vendor": "the_conduit_contributors",
"versions": [
{
"lessThan": "0.8.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-6301",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-06-25T14:41:07.777353Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-06-25T14:43:17.696Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-01T21:33:05.348Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://gitlab.com/famedly/conduit/-/releases/v0.8.0"
},
{
"tags": [
"x_transferred"
],
"url": "https://conduit.rs/changelog/#v0-8-0-2024-06-12"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Conduit",
"vendor": "The Conduit Contributors",
"versions": [
{
"lessThan": "0.8.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Matthias Ahouansou for finding and patching the vulnerability"
}
],
"descriptions": [
{
"lang": "en",
"value": "Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs"
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-346",
"description": "CWE-346: Origin Validation Error",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-08-29T15:04:59.937Z",
"orgId": "ceab7361-8a18-47b1-92ba-4d7d25f6715a",
"shortName": "GitLab"
},
"references": [
{
"url": "https://gitlab.com/famedly/conduit/-/releases/v0.8.0"
},
{
"url": "https://conduit.rs/changelog/#v0-8-0-2024-06-12"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to version 0.8.0"
}
],
"title": "Origin Validation Error in Conduit"
}
},
"cveMetadata": {
"assignerOrgId": "ceab7361-8a18-47b1-92ba-4d7d25f6715a",
"assignerShortName": "GitLab",
"cveId": "CVE-2024-6301",
"datePublished": "2024-06-25T13:02:20.904Z",
"dateReserved": "2024-06-25T10:30:45.683Z",
"dateUpdated": "2024-08-29T15:04:59.937Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2024-6301 (GCVE-0-2024-6301)
Vulnerability from cvelistv5 โ Published: 2024-06-25 13:02 โ Updated: 2024-08-29 15:04
VLAI
EPSS
VEX
Title
Origin Validation Error in Conduit
Summary
Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator ยท CISA-ADP (v2.0.3)
Decision recorded 2024-06-25 14:41 UTC
CWE
- CWE-346 - Origin Validation Error
Assigner
References
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| The Conduit Contributors | Conduit |
Affected:
0 , < 0.8.0
(semver)
|
|
| the_conduit_contributors | conduit |
Affected:
0 , < 0.8.0
(custom)
cpe:2.3:a:the_conduit_contributors:conduit:0.8.0:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:the_conduit_contributors:conduit:0.8.0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "conduit",
"vendor": "the_conduit_contributors",
"versions": [
{
"lessThan": "0.8.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-6301",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-06-25T14:41:07.777353Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-06-25T14:43:17.696Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-01T21:33:05.348Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://gitlab.com/famedly/conduit/-/releases/v0.8.0"
},
{
"tags": [
"x_transferred"
],
"url": "https://conduit.rs/changelog/#v0-8-0-2024-06-12"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Conduit",
"vendor": "The Conduit Contributors",
"versions": [
{
"lessThan": "0.8.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Matthias Ahouansou for finding and patching the vulnerability"
}
],
"descriptions": [
{
"lang": "en",
"value": "Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs"
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-346",
"description": "CWE-346: Origin Validation Error",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-08-29T15:04:59.937Z",
"orgId": "ceab7361-8a18-47b1-92ba-4d7d25f6715a",
"shortName": "GitLab"
},
"references": [
{
"url": "https://gitlab.com/famedly/conduit/-/releases/v0.8.0"
},
{
"url": "https://conduit.rs/changelog/#v0-8-0-2024-06-12"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to version 0.8.0"
}
],
"title": "Origin Validation Error in Conduit"
}
},
"cveMetadata": {
"assignerOrgId": "ceab7361-8a18-47b1-92ba-4d7d25f6715a",
"assignerShortName": "GitLab",
"cveId": "CVE-2024-6301",
"datePublished": "2024-06-25T13:02:20.904Z",
"dateReserved": "2024-06-25T10:30:45.683Z",
"dateUpdated": "2024-08-29T15:04:59.937Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}