Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-6299

Опубликовано: 25 июн. 2024
Источник: nvd
CVSS3: 4.8
CVSS3: 3.7
EPSS Низкий

Описание

Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an expired key to forge requests as the remote server, as well as PDUs with timestamps past the expiry date

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:conduit:conduit:*:*:*:*:*:*:*:*
Версия до 0.8.0 (исключая)

EPSS

Процентиль: 15%
0.00049
Низкий

4.8 Medium

CVSS3

3.7 Low

CVSS3

Дефекты

CWE-324
NVD-CWE-Other

Связанные уязвимости

CVSS3: 4.8
github
около 1 года назад

Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an expired key to forge requests as the remote server, as well as PDUs with timestamps past the expiry date

EPSS

Процентиль: 15%
0.00049
Низкий

4.8 Medium

CVSS3

3.7 Low

CVSS3

Дефекты

CWE-324
NVD-CWE-Other