CVE-2024-6107

Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps.
References
Link Resource
https://bugs.launchpad.net/maas/+bug/2069094 Exploit Issue Tracking Patch
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:canonical:metal_as_a_service:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:metal_as_a_service:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:metal_as_a_service:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:metal_as_a_service:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:metal_as_a_service:3.5.0:*:*:*:*:*:*:*

History

27 Aug 2025, 14:30

Type Values Removed Values Added
Summary
  • (es) Debido a una verificación insuficiente, un atacante podría usar un cliente malicioso para eludir las comprobaciones de autenticación y ejecutar comandos RPC en una región. Esto se ha solucionado en MAAS y se ha actualizado en los snaps correspondientes.
References () https://bugs.launchpad.net/maas/+bug/2069094 - () https://bugs.launchpad.net/maas/+bug/2069094 - Exploit, Issue Tracking, Patch
CWE NVD-CWE-noinfo
First Time Canonical metal As A Service
Canonical
CPE cpe:2.3:a:canonical:metal_as_a_service:3.5.0:*:*:*:*:*:*:*
cpe:2.3:a:canonical:metal_as_a_service:*:*:*:*:*:*:*:*

21 Jul 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-21 09:15

Updated : 2025-08-27 14:30


NVD link : CVE-2024-6107

Mitre link : CVE-2024-6107

CVE.ORG link : CVE-2024-6107


JSON object : View

Products Affected

canonical

  • metal_as_a_service
CWE
CWE-287

Improper Authentication

NVD-CWE-noinfo