CVE-2024-6301

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-6301
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-6301.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-6301
Published
2024-06-25T13:02:20.904Z
Modified
2025-11-28T02:35:43.388934Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Origin Validation Error in Conduit
Details

Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs

Database specific
{
    "cna_assigner": "GitLab",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/6xxx/CVE-2024-6301.json",
    "cwe_ids": [
        "CWE-346"
    ]
}
References

Affected packages

Git / gitlab.com/famedly/conduit

Affected ranges

Type
GIT
Repo
https://gitlab.com/famedly/conduit
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed