Vulnerability Description
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Cloud-Init | < 25.1.3 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-6174?
CVE-2024-6174 is a vulnerability with a CVSS score of 8.8 (HIGH). When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
How severe is CVE-2024-6174?
CVE-2024-6174 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-6174?
Check the references section above for vendor advisories and patch information. Affected products include: Canonical Cloud-Init.