Description
Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine.
Problem types
CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine
Product status
6.0 before 6.5
5.21 before 5.21.4
Credits
GMO Flatt Security Inc.
References
github.com/...al/lxd/security/advisories/GHSA-w2hg-2v4p-vmh6