Impact
An authorization flaw in Canonical LXD’s custom storage volume creation endpoint lets an authenticated client copy any custom volume from another project by sending a crafted request that sets a source volume and source.project but omits source.type. The flaw allows the attacker to read the volume’s data, snapshots, and configuration, exposing sensitive information belonging to other projects.
Affected Systems
The CNA data lists Canonical LXD as the affected product, but no specific versions are provided. The vulnerability applies to installations that expose the custom volume creation API, and the description indicates that it is present in versions 5.0.0 and later until fixed in the releases noted in the advisory.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Attack requires an authenticated client that has permission to create custom volumes in their project, a privilege that is commonly granted. Once authenticated, the exploit is straightforward: craft the request to copy the desired volume, which results in confidential data disclosure across projects.
OpenCVE Enrichment