Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code responses.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Oct 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical lxd |
|
| Vendors & Products |
Canonical
Canonical lxd |
Thu, 02 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 02 Oct 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code responses. | |
| Title | Project existence disclosure in LXD images API | |
| Weaknesses | CWE-209 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: canonical
Published: 2025-10-02T09:25:42.466Z
Updated: 2025-10-02T17:29:54.196Z
Reserved: 2025-07-18T07:59:07.917Z
Link: CVE-2025-54291
Updated: 2025-10-02T17:29:46.451Z
Status : Awaiting Analysis
Published: 2025-10-02T10:15:39.387
Modified: 2025-10-02T19:11:46.753
Link: CVE-2025-54291
No data.
ReportizFlow