3.8 LOW
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): CHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): NONE
- Availability impact (A): NONE
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, …
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
References
-
https://www.cve.org/CVERecord?id=CVE-2024-6219 issue-tracking
-
https://www.cve.org/CVERecord?id=CVE-2024-6219 issue-tracking
-
https://www.cve.org/CVERecord?id=CVE-2024-6219 issue-tracking
-
https://www.cve.org/CVERecord?id=CVE-2024-6219 issue-tracking
-
https://www.cve.org/CVERecord?id=CVE-2024-6219 issue-tracking
-
https://www.cve.org/CVERecord?id=CVE-2024-6219 issue-tracking
Affected products
- <5.21.1
Matching in nixpkgs
pkgs.lxd-ui
Web user interface for LXD
pkgs.lxd-lts
Daemon based on liblxc offering a REST API to manage containers
pkgs.lxdvdrip
Command line tool to make a copy from a video DVD for private use
pkgs.lxd-image-server
Creates and manages a simplestreams lxd image server on top of nginx
pkgs.lxd-unwrapped-lts
Daemon based on liblxc offering a REST API to manage containers
pkgs.emacsPackages.lxd-tramp
None
-
nixos-unstable 20181023.7
- nixpkgs-unstable 20181023.7
- nixos-unstable-small 20181023.7
pkgs.python311Packages.pylxd
Library for interacting with the LXD REST API
pkgs.python312Packages.pylxd
Library for interacting with the LXD REST API
pkgs.terraform-providers.lxd
None
Package maintainers
-
@mkg20001 Maciej Krüger <mkg20001+nix@gmail.com>