Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
References
Configurations
No configuration.
History
18 Mar 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-295 |
06 Dec 2024, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-06 00:15
Updated : 2025-03-18 16:15
NVD link : CVE-2024-6156
Mitre link : CVE-2024-6156
CVE.ORG link : CVE-2024-6156
JSON object : View
Products Affected
No product.
CWE
CWE-295
Improper Certificate Validation