CVE-2024-6302 Information

Description

Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower allowing a local user to redact any message from users on the same server given that they are able to send redaction events.

Reference

https://gitlab.com/famedly/conduit/-/releases/v0.7.0 https://conduit.rs/changelog/#v0-7-0-2024-04-25

Share on: