Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Oct 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Canonical
Canonical lxd Linux Linux linux |
|
Vendors & Products |
Canonical
Canonical lxd Linux Linux linux |
Thu, 02 Oct 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 02 Oct 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints. | |
Title | Project Existence Disclosure via Error Handling in LXD Image Export | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: canonical
Published: 2025-10-02T09:24:12.894Z
Updated: 2025-10-02T17:31:02.699Z
Reserved: 2025-07-18T07:59:07.917Z
Link: CVE-2025-54290

Updated: 2025-10-02T17:30:57.839Z

Status : Awaiting Analysis
Published: 2025-10-02T10:15:39.227
Modified: 2025-10-02T19:11:46.753
Link: CVE-2025-54290

No data.