Path Traversal Vulnerability in Canonical LXD-UI
CVE-2025-54292
4.8MEDIUM
What is CVE-2025-54292?
The vulnerability in Canonical's LXD-UI prior to version 6.5 and 5.21.4 allows remote authenticated attackers to exploit a path traversal flaw. By crafting specific resource names in URL paths, attackers may gain unauthorized access to sensitive resources, potentially leading to data exposure and modification of unintended files on the system.
Affected Version(s)
LXD 6.0 < 6.5
LXD 5.21 < 5.21.4
References
CVSS V4
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
