CyberRota Analysis
AI-GeneratedThe vulnerability affects Canonical LXD versions 5.0.0 and later on Linux, allowing authenticated users with permissions to create custom storage volumes to access and read custom storage volumes from other projects on the server. This is achieved through a crafted request that bypasses proper authorization checks, potentially exposing sensitive data, including snapshots and configurations. Organizations utilizing LXD for container management should prioritize patching to versions 5.0.10, 5.21.8, or 6.10 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the server, including its snapshots and configuration. The client does this with a crafted request that sets a source volume and source.project but omits source.type.