Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-6219

Опубликовано: 06 дек. 2024
Источник: debian
EPSS Низкий

Описание

Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lxdnot-affectedpackage
incusnot-affectedpackage

Примечания

  • https://github.com/canonical/lxd/security/advisories/GHSA-jpmc-7p9c-4rxf

  • lxd: https://github.com/canonical/lxd/commit/5cdc9a35b9c51e981b1e70330bde0413ccacc7fd (lxd-5.20)

  • incus: https://github.com/lxc/incus/commit/d2bb0d86031cb0c1319914f1fb3842c058edb776 (v0.3.0)

EPSS

Процентиль: 37%
0.00157
Низкий

Связанные уязвимости

CVSS3: 3.8
ubuntu
около 1 года назад

Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.

CVSS3: 3.8
nvd
около 1 года назад

Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.

CVSS3: 3.8
github
около 1 года назад

lxd has a restricted TLS certificate privilege escalation when in PKI mode

EPSS

Процентиль: 37%
0.00157
Низкий