CVE-2024-6219: Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its...

3.8 CVSS

Description

Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.

Classification

CVE ID: CVE-2024-6219

CVSS Base Severity: LOW

CVSS Base Score: 3.8

Affected Products

Vendor: Canonical Ltd.

Product: LXD

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.44% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://github.com/canonical/lxd/security/advisories/GHSA-jpmc-7p9c-4rxf
https://www.cve.org/CVERecord?id=CVE-2024-6219

Timeline