CVE-2020-14301
Dashboard / Vulnerabilities / CVE-2020-14301
Summary:
Details: An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.
References: https://security.netapp.com/advisory/ntap-20210629-0007/, https://bugzilla.redhat.com/show_bug.cgi?id=1848640
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 07bb8ff4dd0ca0224754c582390f4a873597c4b9
Affected versions
v6.3.0-rc1
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
