Impact
The vulnerability is a missing authorization check in the imageDownload operation that allows a client bound to one project to download images from another project when the images share the same local fingerprint. This flaw constitutes an incomplete permission check (CWE-862) and enables the theft of private image data. An attacker who can invoke the image or instance import API on the host can obtain binaries or configuration files that belong solely to a different project, potentially revealing sensitive configuration or application artifacts.
Affected Systems
Canonical LXD containers before versions 5.0.10, 5.21.8, and 6.10 running on Linux are affected. Users operating LXD with multiple projects on the same host may unintentionally expose private images if they share common fingerprints during imports.
Risk and Exploitability
The CVSS score of 6.3 indicates a medium security impact. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog, suggesting the exploitation likelihood is currently unclear. The vulnerability requires local access to the LXD server endpoint; the client must be authenticated under its own project. Thus, the attack vector is inferred to be local and limited to the host environment.
OpenCVE Enrichment