CVE Vulnerabilities

CVE-2024-6156

Improper Certificate Validation

Published: Dec 06, 2024 | Modified: Mar 18, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Mark Laing discovered that LXDs PKI mode, until version 5.21.2, could be bypassed if the clients certificate was present in the trust store.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Potential Mitigations

References