PT-2020-6394 · Libvirt+5 · Libvirt+5

Published

2020-05-08

·

Updated

2022-05-13

·

CVE-2020-14301

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libvirt versions prior to 6.3.0
Description The issue is related to the preservation of HTTP cookie data in the XML dump of a guest domain, potentially allowing a remote attacker to access sensitive information within the domain configuration. This can be achieved through the dumpxml command.
Recommendations For versions prior to 6.3.0, update to version 6.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the dumpxml command to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:4676
ALT-PU-2020-1938
BDU:2021-04593
CESA-2020_4676
CVE-2020-14301
RHSA-2020:4676
RHSA-2020_4676
RLSA-2020:4676

Affected Products

Alt Linux
Almalinux
Centos
Red Hat
Rocky Linux
Libvirt