Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54707 | When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration. |
Ubuntu USN |
USN-7677-1 | cloud-init vulnerabilities |
Tue, 26 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:canonical:cloud-init:*:*:*:*:*:*:*:* |
Tue, 08 Jul 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | cloud-init: From CVEorg collector | cloud-init: Cloud init permissions flaw |
Fri, 27 Jun 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | cloud-init: From CVEorg collector | |
| Weaknesses | CWE-276 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 26 Jun 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 |
Thu, 26 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Jun 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2025-06-26T17:38:50.843Z
Reserved: 2024-06-19T22:11:48.245Z
Link: CVE-2024-6174
Updated: 2025-06-26T13:29:51.276Z
Status : Analyzed
Published: 2025-06-26T10:15:25.133
Modified: 2025-08-26T20:48:56.763
Link: CVE-2024-6174
OpenCVE Enrichment
Updated: 2025-07-06T22:16:32Z
EUVD
Ubuntu USN