CVE-2024-6107: Canonical Metal As A Service
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps.
Affected products
- Canonical Metal As A Service: from 3.1.0, before 3.1.4 (fixed in 3.1.4); from 3.2.0, before 3.2.11 (fixed in 3.2.11); from 3.3.0, before 3.3.8 (fixed in 3.3.8); from 3.4.0, before 3.4.4 (fixed in 3.4.4); version 3.5.0 only
Published 2025-07-21. Last modified 2026-06-17.