Описание
Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-apps/focal | not-affected | installs LXD snap |
| esm-infra/bionic | not-affected | no web UI |
| esm-infra/xenial | not-affected | no web UI |
| jammy | DNE | |
| noble | DNE | |
| plucky | DNE | |
| questing | DNE | |
| upstream | released | 5.0.5, 5.21.4, 6.5 |
Показывать по
8.8 High
CVSS3
Связанные уязвимости
Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication.
Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions ...
Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI
8.8 High
CVSS3