CVE Vulnerabilities

CVE-2024-6174

Improper Authentication

Published: Jun 26, 2025 | Modified: Aug 26, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.8 IMPORTANT
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Cloud-initCanonical*25.1.3 (excluding)
Red Hat Enterprise Linux 10RedHatcloud-init-0:24.4-3.el10_0.2*
Red Hat Enterprise Linux 8RedHatcloud-init-0:23.4-7.el8_10.10*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatcloud-init-0:21.1-15.el8_6.4*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatcloud-init-0:21.1-15.el8_6.4*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatcloud-init-0:21.1-15.el8_6.4*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatcloud-init-0:22.1-8.el8_8.2*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatcloud-init-0:22.1-8.el8_8.2*
Red Hat Enterprise Linux 9RedHatcloud-init-0:24.4-4.el9_6.3*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatcloud-init-0:21.1-19.el9_0.7*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatcloud-init-0:22.1-10.el9_2.1*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatcloud-init-0:23.4-7.el9_4.13*
Cloud-initUbuntudevel*
Cloud-initUbuntuesm-infra/bionic*
Cloud-initUbuntuesm-infra/focal*
Cloud-initUbuntuesm-infra/xenial*
Cloud-initUbuntufocal*
Cloud-initUbuntujammy*
Cloud-initUbuntumantic*
Cloud-initUbuntunoble*
Cloud-initUbuntuoracular*
Cloud-initUbuntuplucky*
Cloud-initUbuntuupstream*

Potential Mitigations

References