CVE Vulnerabilities

CVE-2024-6156

Improper Certificate Validation

Published: Dec 06, 2024 | Modified: Mar 18, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io minimus.io echohq.com

Mark Laing discovered that LXDs PKI mode, until version 5.21.2, could be bypassed if the clients certificate was present in the trust store.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Lxd Ubuntu focal *

Potential Mitigations

References