Описание
Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-apps/focal | not-affected | installs LXD snap |
| esm-infra/bionic | ignored | backporting risks regressions |
| esm-infra/xenial | ignored | backporting risks regressions |
| jammy | DNE | |
| noble | DNE | |
| plucky | DNE | |
| questing | DNE | |
| upstream | needs-triage |
Показывать по
10
EPSS
Процентиль: 12%
0.0004
Низкий
8.1 High
CVSS3
Связанные уязвимости
CVSS3: 8.1
nvd
6 месяцев назад
Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format
CVSS3: 8.1
debian
6 месяцев назад
Privilege Escalation in operations API in Canonical LXD <6.5 on multip ...
CVSS3: 6.8
github
6 месяцев назад
Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API
EPSS
Процентиль: 12%
0.0004
Низкий
8.1 High
CVSS3