-
Notifications
You must be signed in to change notification settings - Fork 72
Closed
Labels
Description
Advisory CVE-2024-6219 references a vulnerability in the following Go modules:
| Module |
|---|
| github.com/canonical/lxd |
Description:
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
References:
Cross references:
- github.com/canonical/lxd appears in 1 other report(s):
- data/excluded/GO-2023-2384.yaml (x/vulndb: potential Go vuln in github.com/canonical/lxd: GHSA-x9qq-236j-gj97 #2384) NOT_A_VULNERABILITY
See doc/quickstart.md for instructions on how to triage this report.
id: GO-ID-PENDING
modules:
- module: github.com/canonical/lxd
vulnerable_at: 0.0.0-20241205110837-ac7aa741dc57
summary: CVE-2024-6219 in github.com/canonical/lxd
cves:
- CVE-2024-6219
references:
- advisory: https://www.cve.org/CVERecord?id=CVE-2024-6219
- web: https://github.com/canonical/lxd/security/advisories/GHSA-jpmc-7p9c-4rxf
source:
id: CVE-2024-6219
created: 2024-12-06T01:01:45.420224403Z
review_status: UNREVIEWED