Описание
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| lxd | not-affected | package | ||
| incus | not-affected | package |
Примечания
https://github.com/canonical/lxd/security/advisories/GHSA-jpmc-7p9c-4rxf
lxd: https://github.com/canonical/lxd/commit/5cdc9a35b9c51e981b1e70330bde0413ccacc7fd (lxd-5.20)
incus: https://github.com/lxc/incus/commit/d2bb0d86031cb0c1319914f1fb3842c058edb776 (v0.3.0)
EPSS
Связанные уязвимости
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
lxd has a restricted TLS certificate privilege escalation when in PKI mode
EPSS