Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://github.com/canonical/lxd/security/advisories/GHSA-4c49-9fpc-hc3v | issue tracking |
https://www.cve.org/CVERecord?id=CVE-2024-6156 | issue tracking |