CVE-2024-6299

Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an expired key to forge requests as the remote server, as well as PDUs with timestamps past the expiry date
Configurations

Configuration 1 (hide)

cpe:2.3:a:conduit:conduit:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:49

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 3.7
v2 : unknown
v3 : 4.8
References () https://conduit.rs/changelog/#v0-8-0-2024-06-12 - Release Notes () https://conduit.rs/changelog/#v0-8-0-2024-06-12 - Release Notes
References () https://gitlab.com/famedly/conduit/-/releases/v0.8.0 - Release Notes () https://gitlab.com/famedly/conduit/-/releases/v0.8.0 - Release Notes

20 Sep 2024, 19:24

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.8
v2 : unknown
v3 : 3.7
Summary
  • (es) Falta de consideración de la caducidad de la clave al validar firmas en Conduit, lo que permite a un atacante que ha comprometido una clave caducada falsificar solicitudes como servidor remoto, así como PDU con marcas de tiempo posteriores a la fecha de caducidad.
CPE cpe:2.3:a:conduit:conduit:*:*:*:*:*:*:*:*
CWE NVD-CWE-Other
References () https://conduit.rs/changelog/#v0-8-0-2024-06-12 - () https://conduit.rs/changelog/#v0-8-0-2024-06-12 - Release Notes
References () https://gitlab.com/famedly/conduit/-/releases/v0.8.0 - () https://gitlab.com/famedly/conduit/-/releases/v0.8.0 - Release Notes
First Time Conduit conduit
Conduit

25 Jun 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-25 13:15

Updated : 2024-11-21 09:49


NVD link : CVE-2024-6299

Mitre link : CVE-2024-6299

CVE.ORG link : CVE-2024-6299


JSON object : View

Products Affected

conduit

  • conduit
CWE
CWE-324

Use of a Key Past its Expiration Date

NVD-CWE-Other