PT-2019-11608 · Red Hat+2 · Virt-Manager+3
Prasad Pandit
·
Publicado
2019-07-03
·
Atualizado
2024-06-15
·
CVE-2019-10183
CVSS v3.1
3.3
Baixa
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
virt-manager version 2.2.0
Description:
The virt-install utility has introduced an option '--unattended' to create virtual machines without user interaction. This option accepts the guest VM password as command line arguments, potentially leaking them to other users on the system via process listing.
Recommendations:
For virt-manager version 2.2.0, consider avoiding the use of the '--unattended' option until a secure alternative is available, or restrict access to process listings to minimize the risk of password exposure.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Red Hat
Virt-Manager