Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
History

Fri, 06 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Canonical
Canonical lxd
CPEs cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
Vendors & Products Canonical
Canonical lxd
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Dec 2024 23:30:00 +0000

Type Values Removed Values Added
Description Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published: 2024-12-05T23:11:04.815Z

Updated: 2024-12-10T18:07:48.004Z

Reserved: 2024-06-18T22:34:39.949Z

Link: CVE-2024-6156

cve-icon Vulnrichment

Updated: 2024-12-06T16:39:56.800Z

cve-icon NVD

Status : Received

Published: 2024-12-06T00:15:04.380

Modified: 2024-12-06T00:15:04.380

Link: CVE-2024-6156

cve-icon Redhat

No data.