Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-6174

Опубликовано: 26 июн. 2025
Источник: debian

Описание

When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cloud-initunfixedpackage

Примечания

  • Fixed by: https://github.com/canonical/cloud-init/commit/f43937f0b462734eb9c76700491c18fe4133c8e1 (25.1.3)

  • https://github.com/advisories/GHSA-w8g9-wp36-fchj

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 2 месяцев назад

When a non-x86 platform is detected, cloud-init grants root access to a hard coded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.

CVSS3: 8.8
redhat
около 2 месяцев назад

When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.

CVSS3: 8.8
nvd
около 2 месяцев назад

When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.

CVSS3: 8.8
github
около 2 месяцев назад

When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.