CVE-2024-6301: Conduit
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs
Affected products
- Conduit Conduit: before 0.8.0 (fixed in 0.8.0)
Published 2024-06-25. Last modified 2026-06-17.