Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5qrf-45p7-8vrc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the dumpxml command.

An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the dumpxml command.

EPSS

Процентиль: 50%
0.00264
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-212

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 4 лет назад

An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.

CVSS3: 6.5
redhat
больше 5 лет назад

An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.

CVSS3: 6.5
nvd
около 4 лет назад

An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.

CVSS3: 6.5
debian
около 4 лет назад

An information disclosure vulnerability was found in libvirt in versio ...

CVSS3: 6.5
fstec
около 5 лет назад

Уязвимость файлов cookie HTTP библиотеки управления виртуализацией Libvirt, связанная с неправильным межграничным удалением критичных данных, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 50%
0.00264
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-212