Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints.
History

Fri, 03 Oct 2025 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Canonical
Canonical lxd
Linux
Linux linux
Vendors & Products Canonical
Canonical lxd
Linux
Linux linux

Thu, 02 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Oct 2025 09:30:00 +0000

Type Values Removed Values Added
Description Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints.
Title Project Existence Disclosure via Error Handling in LXD Image Export
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published: 2025-10-02T09:24:12.894Z

Updated: 2025-10-02T17:31:02.699Z

Reserved: 2025-07-18T07:59:07.917Z

Link: CVE-2025-54290

cve-icon Vulnrichment

Updated: 2025-10-02T17:30:57.839Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-02T10:15:39.227

Modified: 2025-10-02T19:11:46.753

Link: CVE-2025-54290

cve-icon Redhat

No data.