CVE-2024-6156

Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-12-06 00:15

Updated : 2025-08-26 17:22


NVD link : CVE-2024-6156

Mitre link : CVE-2024-6156

CVE.ORG link : CVE-2024-6156


JSON object : View

Products Affected

canonical

  • lxd
CWE
CWE-295

Improper Certificate Validation