Описание
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
Релиз | Статус | Примечание |
---|---|---|
devel | released | 1.2.8-0ubuntu14 |
esm-infra-legacy/trusty | released | 1.2.2-0ubuntu13.1.7 |
lucid | not-affected | 0.7.5-5ubuntu27.24 |
precise | not-affected | 0.9.8-2ubuntu17.20 |
trusty | released | 1.2.2-0ubuntu13.1.7 |
trusty/esm | released | 1.2.2-0ubuntu13.1.7 |
upstream | needs-triage | |
utopic | released | 1.2.8-0ubuntu11.1 |
Показывать по
EPSS
5 Medium
CVSS2
Связанные уязвимости
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote rea ...
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
ELSA-2015-0008: libvirt security and bug fix update (LOW)
EPSS
5 Medium
CVSS2