Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower, allowing a local user to redact any message from users on the same server, given that they are able to send redaction events.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Conduit | Conduit | * | 0.7.0 (excluding) |