Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
Conduit
HIGH 8.8
CVE-2024-6303
Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for …
Fix: 0.8.0+
Fix from $1,950
2024-06-25
Conduit
HIGH 7.5
CVE-2024-6301
Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs
Fix: 0.8.0+
Fix from $1,950
2024-06-25
Conduit
MEDIUM 5.5
CVE-2024-6302
Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower, allowing a local user to redact any message from users o…
Fix: 0.7.0+
Fix from $1,600
2024-06-25
Conduit
MEDIUM 5.3
CVE-2024-6300
Incomplete cleanup when performing redactions in Conduit, allowing an attacker to check whether certain strings were present in the PDU before redact…
Fix: 0.8.0+
Fix from $1,600
2024-06-25