Critical severity9.6NVD Advisory· Published Jul 21, 2025· Updated Jun 17, 2026
CVE-2024-6107
CVE-2024-6107
Description
Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:canonical:metal_as_a_service:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:canonical:metal_as_a_service:*:*:*:*:*:*:*:*range: >=3.1.0,<3.1.4
- cpe:2.3:a:canonical:metal_as_a_service:3.5.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- bugs.launchpad.net/maas/+bug/2069094nvdExploitIssue TrackingPatch
News mentions
0No linked articles in our index yet.