PT-2024-37461 · Canonical · Lxd
Markylaing
·
Published
2024-12-02
·
Updated
2025-11-13
·
CVE-2024-6219
CVSS v3.1
3.8
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
LXD versions prior to 5.21.1
Description:
A restricted certificate could be added to the trust store with its restrictions not honoured in LXD's PKI mode. This occurs when the
core.trust ca certificates configuration option is disabled, causing restrictions applied to a certificate to be ignored due to the presence of a server.ca file in LXD DIR. The issue allows a client with a restricted certificate to have full access to LXD.Recommendations:
For versions prior to 5.21.1, update to version 5.21.1 or later to resolve the issue. As a temporary workaround, consider disabling the PKI mode or enabling the
core.trust ca certificates configuration option to allow for passwordless PKI with CRL revocation. Restrict access to the trust store to minimize the risk of exploitation. Avoid adding restricted certificates to the trust store until the issue is resolved.Fix
Improper Authentication
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lxd