CVE-2025-54287 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitra…
High CVSS: 7.1

CVE-2025-54287

Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration
permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine.
Vendor
Canonical
Product
Lxd
CWE
CWE-1336
Yayın Tarihi
2025-10-02 10:15:38
Güncelleme
2025-10-22 15:39:01
Source Identifier
security@ubuntu.com
KEV Date Added
-

Kategoriler

Referanslar