PT-2025-40334 · Canonical+2 · Lxd+2
Published
2025-10-02
·
Updated
2025-11-17
·
CVE-2025-54291
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Canonical LXD versions prior to 6.5
Canonical LXD versions prior to 5.21.4
Description
An information disclosure issue exists in the images API of Canonical LXD. This allows unauthenticated remote attackers to determine project existence by observing differing HTTP status code responses.
Recommendations
Update to a version prior to 6.5.
Update to a version prior to 5.21.4.
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Lxd
Red Os