PT-2026-99891 · Canonical · Lxd
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Canonical LXD versions 4.0.2 through 4.0.13
Canonical LXD version 5.0.10
Canonical LXD version 5.21.8
Canonical LXD version 6.10
Description
A path traversal issue exists in the CLI client image export and copy functionality. A remote malicious or machine-in-the-middle image server can overwrite arbitrary local files and execute code on the client system. This is achieved by using a crafted
filename parameter within the Content-Disposition header during unified image export or copy operations targeting a local directory.Recommendations
Update Canonical LXD version 4.0.2 through 4.0.13 to version 4.0.14.
Update Canonical LXD version 5.0.10 to a newer version.
Update Canonical LXD version 5.21.8 to a newer version.
Update Canonical LXD version 6.10 to a newer version.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lxd