CVE-2024-6156

LOW3.8EPSS 0.05%

CA certificate sign check bypass in github.com/canonical/lxd

發布日:2024/12/9修改日:2026/4/28

描述

Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.

受影響套件(4)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1LOW3.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

參考連結(7)