Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14301

Опубликовано: 14 апр. 2020
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the dumpxml command.

An information disclosure vulnerability was found in libvirt. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw could allow a malicious user with a read-only connection to access potentially sensitive information in the domain configuration via the dumpxml command.

Отчет

Support for cookies for HTTP based disks was introduced in libvirt upstream version 6.2.0. Red Hat Enterprise Linux 5, 6, 7 and 8 are not affected by this issue, as they ship older versions of the libvirt package. Red Hat Enterprise Linux Advanced Virtualization 8 is the only affected product.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libvirtNot affected
Red Hat Enterprise Linux 6libvirtNot affected
Red Hat Enterprise Linux 7libvirtNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/libvirtAffected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.3/libvirtAffected
Advanced Virtualization for RHEL 8.2.1virtFixedRHBA-2020:317228.07.2020
Advanced Virtualization for RHEL 8.2.1virt-develFixedRHBA-2020:317228.07.2020
Red Hat Enterprise Linux 8virt-develFixedRHSA-2020:467604.11.2020
Red Hat Enterprise Linux 8virtFixedRHSA-2020:467604.11.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-212
https://bugzilla.redhat.com/show_bug.cgi?id=1848640libvirt: leak of sensitive cookie information via dumpxml

EPSS

Процентиль: 50%
0.00264
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 4 лет назад

An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.

CVSS3: 6.5
nvd
около 4 лет назад

An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.

CVSS3: 6.5
debian
около 4 лет назад

An information disclosure vulnerability was found in libvirt in versio ...

CVSS3: 6.5
github
около 3 лет назад

An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.

CVSS3: 6.5
fstec
около 5 лет назад

Уязвимость файлов cookie HTTP библиотеки управления виртуализацией Libvirt, связанная с неправильным межграничным удалением критичных данных, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 50%
0.00264
Низкий

6.5 Medium

CVSS3