Description
Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
Product status
4.0 (semver) before 4.0.10
4.0 (semver) before 5.0.4
4.0 (semver) before 5.21.2
4.0 (semver) before 6.1
References
github.com/...al/lxd/security/advisories/GHSA-4c49-9fpc-hc3v
www.cve.org/CVERecord?id=CVE-2024-6156