Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted log file names or symbolic links.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Oct 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Canonical
Canonical lxd Linux Linux linux |
|
Vendors & Products |
Canonical
Canonical lxd Linux Linux linux |
Thu, 02 Oct 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 02 Oct 2025 11:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted log file names or symbolic links. | |
Title | Path Traversal in LXD Instance Log File Retrieval | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: canonical
Published: 2025-10-02T10:43:58.246Z
Updated: 2025-10-02T15:53:20.364Z
Reserved: 2025-07-18T07:59:07.917Z
Link: CVE-2025-54293

Updated: 2025-10-02T15:29:39.925Z

Status : Awaiting Analysis
Published: 2025-10-02T11:15:30.540
Modified: 2025-10-02T19:11:46.753
Link: CVE-2025-54293

No data.