Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 02 Oct 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints. | |
Title | Project Existence Disclosure via Error Handling in LXD Image Export | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2025-10-02T10:43:53.703Z
Reserved: 2025-07-18T07:59:07.917Z
Link: CVE-2025-54290

No data.

Status : Received
Published: 2025-10-02T10:15:39.227
Modified: 2025-10-02T10:15:39.227
Link: CVE-2025-54290

No data.

No data.