CVE-2024-6107
21.07.2025, 09:15
Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps.Enginsight
Vendor | Product | Version |
---|---|---|
canonical | metal_as_a_service | 3.1.0 ≤ 𝑥 < 3.1.4 |
canonical | metal_as_a_service | 3.2.0 ≤ 𝑥 < 3.2.11 |
canonical | metal_as_a_service | 3.3.0 ≤ 𝑥 < 3.3.8 |
canonical | metal_as_a_service | 3.4.0 ≤ 𝑥 < 3.4.4 |
canonical | metal_as_a_service | 3.5.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration