cbcvebase.
CVE-2024-6219
published 2024-12-06

CVE-2024-6219: Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not…

low3.8CVSS 3.1
AVLACLPRLUINSCCLINAN
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.

Affected

5 ranges
VendorProductVersion rangeFixed in
canonicallxd< 5.21.15.21.1
canonical_ltdlxd< 5.21.15.21.1
debianincus
debianlxd
github.comcanonical_lxd>= 0 < 0.0.0-20240403103450-0e7f2b5bf4d20.0.0-20240403103450-0e7f2b5bf4d2

CVSS provenance

nvdv3.13.8LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
osv3.8LOW