← Back

CVE-2024-6156

nvd nist
Published: Dec 6, 2024Modified: Jun 17, 2026

JSON object

Loading...
3.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Exploitability: 2.0 / Impact: 1.4
Source: security@ubuntu.com (Secondary)

Description

Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.

Affected (3)

Products: Canonical: Lxd
1 product
Lxd
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
From 4.0.0 to 4.0.10
From 5.0.0 to 5.0.4
From 5.1 to 5.21.2

References (2)

Source: security@ubuntu.com
ExploitVendor Advisory
Source: security@ubuntu.com
Third Party Advisory

Timeline

No history available yet.