CVE-2024-6301

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-6301
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-6301.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-6301
Published
2024-06-25T13:02:20.904Z
Modified
2025-12-02T00:24:11.735776Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Origin Validation Error in Conduit
Details

Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/6xxx/CVE-2024-6301.json",
    "cna_assigner": "GitLab",
    "cwe_ids": [
        "CWE-346"
    ]
}
References

Affected packages

Git / gitlab.com/famedly/conduit

Affected ranges

Type
GIT
Repo
https://gitlab.com/famedly/conduit
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.2.0
v0.3.0
v0.4.0
v0.5.0
v0.6.0
v0.7.0

Database specific

source

"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-6301.json"