Описание
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.
Ссылки
- Issue TrackingPatch
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 6.6 (включая) до 6.9 (исключая)
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
EPSS
Процентиль: 21%
0.00288
Низкий
8.4 High
CVSS3
9.6 Critical
CVSS3
Дефекты
CWE-639
Связанные уязвимости
CVSS3: 8.4
ubuntu
2 месяца назад
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.
CVSS3: 8.4
debian
2 месяца назад
Broken Access Control in the devLXDInstancePatchHandler component of C ...
EPSS
Процентиль: 21%
0.00288
Низкий
8.4 High
CVSS3
9.6 Critical
CVSS3
Дефекты
CWE-639