CyberRota Analysis
AI-GeneratedThe S3 protocol upload endpoint in Incus versions prior to 7.1.0 is vulnerable to path traversal, enabling attackers to create arbitrary files on the host system. This flaw could lead to arbitrary command execution, posing a critical risk to system integrity and security. Organizations using affected versions of Incus should prioritize upgrading to version 7.1.0 or later to mitigate this vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.