CVE-2024-6107: Critical severity Canonical Metal As A Service vulnerability
Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6107?
CVE-2024-6107 has been classified with a medium severity level as it allows attackers to bypass authentication checks.
How do I fix CVE-2024-6107?
To fix CVE-2024-6107, update to a patched version of Metal As A Service beyond the vulnerable versions listed in the vulnerability details.
Which versions of Canonical Metal As A Service are affected by CVE-2024-6107?
CVE-2024-6107 affects Canonical Metal As A Service versions 3.1.0 to 3.1.4, 3.2.0 to 3.2.11, 3.3.0 to 3.3.8, 3.4.0 to 3.4.4, and version 3.5.0.
What kind of attack does CVE-2024-6107 enable?
CVE-2024-6107 enables an attacker to bypass authentication and run RPC commands maliciously.
Is there a known exploit for CVE-2024-6107?
While an exploit for CVE-2024-6107 may exist, it has been mitigated in patched versions of the software.