CVE-2020-14301
—CVSS 3.1
6.5 medium
EPSS
1%p66
Published
()
Modified
Description
An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.
- Vendors
- redhatnetapp
- Products
- libvirt, enterprise linux, enterprise linux eus, enterprise linux for ibm z systems, enterprise linux for ibm z systems eus, enterprise linux for power little endian, enterprise linux for power little endian eus, enterprise linux server aus, enterprise linux server for power little endian update services for sap solutions, enterprise linux server update services for sap solutions, enterprise linux tus, ontap select deploy administration utility
- Weakness
- CWE-212
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.