Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rjmw-frq7-qf5g

Опубликовано: 25 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for privilege escalation by moving the #admins alias to a room which they control, allowing them to run commands resetting passwords, siging json with the server's key, deactivating users, and more

Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for privilege escalation by moving the #admins alias to a room which they control, allowing them to run commands resetting passwords, siging json with the server's key, deactivating users, and more

EPSS

Процентиль: 57%
0.00357
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 9.9
nvd
больше 1 года назад

Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for privilege escalation by moving the #admins alias to a room which they control, allowing them to run commands resetting passwords, siging json with the server's key, deactivating users, and more

EPSS

Процентиль: 57%
0.00357
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-862