blob: b8ad53cc8fc167dd9781c0849e4b14f09cd229f6 [file]
id: GO-2025-3999
modules:
- module: github.com/canonical/lxd
non_go_versions:
- introduced: 0.0.0-20200331193331-03aab09f5b5c
- fixed: 0.0.0-20250827065555-0494f5d47e41
- introduced: 4.0.0
- fixed: 5.21.4
- introduced: 6.0.0
- fixed: 6.5.0
summary: |-
Privilege Escalation via WebSocket Connection
Hijacking in Operations API in github.com/canonical/lxd
cves:
- CVE-2025-54289
ghsas:
- GHSA-3g72-chj4-2228
references:
- advisory: https://github.com/canonical/lxd/security/advisories/GHSA-3g72-chj4-2228
notes:
- Pseudoversions specified in advisory are insufficient to accurately mark go_versions.
source:
id: GHSA-3g72-chj4-2228
created: 2025-11-03T13:06:46.85112-05:00
review_status: REVIEWED