Description
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:NExploitability: 2.0 | Impact: 1.4Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Changed
Confidentiality: Low
Integrity: None
Availability: None
Affected Packages3 packages
🔴Vulnerability Details
5OSVlxd has a restricted TLS certificate privilege escalation when in PKI mode↗2024-12-09 ▶ GHSAlxd has a restricted TLS certificate privilege escalation when in PKI mode↗2024-12-09 ▶ OSVRestricted TLS certificate privilege escalation when in PKI mode in github.com/canonical/lxd↗2024-12-09 ▶ OSVCVE-2024-6219: Mark Laing discovered in LXD's PKI mode, until version 5↗2024-12-06 ▶ CVEListCVE-2024-6219: Mark Laing discovered in LXD's PKI mode, until version 5↗2024-12-05 ▶ 📋Vendor Advisories
1DebianCVE-2024-6219: incus - Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted...↗2024 ▶