Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication.
| Software | From | Fixed in |
|---|---|---|
github.com/canonical/lxd
|
5.0 | 5.0.5 |
github.com/canonical/lxd
|
5.1 | 5.21.4 |
github.com/canonical/lxd
|
6.0 | 6.5 |
github.com/canonical/lxd
|
0.0.0-20220401034332-1e1349e3cbf3 | 0.0.0-20250827065555-0494f5d47e41 |
| canonical / lxd | 5.0.0 | 5.0.5 |
| canonical / lxd | 5.21.0 | 5.21.4 |
| canonical / lxd | 6.1 | 6.5 |