Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-6174

Опубликовано: 26 июн. 2025
Источник: debian
EPSS Низкий

Описание

When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cloud-initfixed25.1.4-1package
cloud-initfixed22.4.2-1+deb12u3bookwormpackage
cloud-initpostponedbullseyepackage

Примечания

  • Fixed by: https://github.com/canonical/cloud-init/commit/f43937f0b462734eb9c76700491c18fe4133c8e1 (25.1.3)

  • https://github.com/advisories/GHSA-w8g9-wp36-fchj

EPSS

Процентиль: 13%
0.00042
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
5 месяцев назад

When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.

CVSS3: 8.8
redhat
5 месяцев назад

When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.

CVSS3: 8.8
nvd
5 месяцев назад

When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.

CVSS3: 8.8
msrc
4 месяца назад

When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.

CVSS3: 8.8
github
5 месяцев назад

When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.

EPSS

Процентиль: 13%
0.00042
Низкий