Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4225-xq9f-4ww3

Опубликовано: 04 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.

EPSS

Процентиль: 21%
0.00067
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 6.3
ubuntu
около 4 лет назад

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 3
redhat
почти 5 лет назад

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 6.3
nvd
около 4 лет назад

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 6.3
msrc
около 4 лет назад

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 6.3
debian
около 4 лет назад

A flaw was found in libvirt while it generates SELinux MCS category pa ...

EPSS

Процентиль: 21%
0.00067
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-732