#VU112884 Insufficient verification of data authenticity in cloud-init - CVE-2024-6174
Published: July 14, 2025
cloud-init
Canonical Ltd.
Description
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists in the way the application identified the boot data source. An attacker can create a rogue service on the local network to impersonate an openstack endpoint and provide root-configuration data to cloud-init on instance launch leading to a security backdoor to root during system boot.