Skip to content

x/vulndb: potential Go vuln in github.com/canonical/lxd: CVE-2024-6219 #3313

@GoVulnBot

Description

@GoVulnBot

Advisory CVE-2024-6219 references a vulnerability in the following Go modules:

Module
github.com/canonical/lxd

Description:
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/canonical/lxd
      vulnerable_at: 0.0.0-20241205110837-ac7aa741dc57
summary: CVE-2024-6219 in github.com/canonical/lxd
cves:
    - CVE-2024-6219
references:
    - advisory: https://www.cve.org/CVERecord?id=CVE-2024-6219
    - web: https://github.com/canonical/lxd/security/advisories/GHSA-jpmc-7p9c-4rxf
source:
    id: CVE-2024-6219
    created: 2024-12-06T01:01:45.420224403Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions