In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS certificate users, allowing a remote authenticated attacker to escalate privileges to cluster admin.
The vulnerability affects the doCertificateUpdate function in the lxd/certificates.go file. When a restricted TLS certificate user sends a PUT or PATCH request to the /1.0/certificates/{fingerprint} endpoint, the LXD server does not validate the Type field in the request body. An attacker can modify this field to escalate their privilege level to cluster administrator role without required authorization.
An authenticated attacker with limited TLS certificate user privileges can obtain full cluster administrator permissions in LXD, giving them control over the entire container environment, including all cluster nodes and hosted resources.
Canonical LXD must be updated to a version higher than 6.7, which introduces a fix for Type field validation. Details are available in the vendor references: https://github.com/canonical/lxd/pull/17936 and https://github.com/canonical/lxd/security/advisories/GHSA-c3h3-89qf-jqm5
Canonical LXD in versions 4.12 to 6.7 inclusive
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HCanonical Lxd
APPCanonical4.12 – 5.0.65.21.0 – 5.21.46.0 – 6.7
Related vulnerabilities
Canonical LXD — privilege escalation przez niekompletną listę blokad VM
Canonical LXD: pominięcie ograniczeń projektu przy imporcie backupu
LXD: privilege escalation przez przywracanie snapshotów z pominięciem polityk
Canonical LXD: nieuprawniony dostęp do woluminów innych gości przez /dev/lxd
Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read p...