Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints.
Metrics
Affected Vendors & Products
References
History
Fri, 24 Oct 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux linux Kernel
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux linux Kernel
|
|
| Metrics |
cvssV3_1
|
Fri, 03 Oct 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical lxd Linux Linux linux |
|
| Vendors & Products |
Canonical
Canonical lxd Linux Linux linux |
Thu, 02 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 02 Oct 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints. | |
| Title | Project Existence Disclosure via Error Handling in LXD Image Export | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: canonical
Published: 2025-10-02T09:24:12.894Z
Updated: 2025-10-02T17:31:02.699Z
Reserved: 2025-07-18T07:59:07.917Z
Link: CVE-2025-54290
Updated: 2025-10-02T17:30:57.839Z
Status : Analyzed
Published: 2025-10-02T10:15:39.227
Modified: 2025-10-24T14:20:05.930
Link: CVE-2025-54290
No data.