CVE-2020-14301
27.05.2021, 20:15
An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | libvirt | 6.2.0 ≤ 𝑥 < 6.3.0 |
redhat | enterprise_linux | 8.0 |
redhat | enterprise_linux_eus | 8.4 |
redhat | enterprise_linux_for_ibm_z_systems | 8.0 |
redhat | enterprise_linux_for_ibm_z_systems_eus | 8.4 |
redhat | enterprise_linux_for_power_little_endian | 8.0 |
redhat | enterprise_linux_for_power_little_endian_eus | 8.4 |
redhat | enterprise_linux_server_aus | 8.4 |
redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 8.4 |
redhat | enterprise_linux_server_update_services_for_sap_solutions | 8.4 |
redhat | enterprise_linux_tus | 8.4 |
netapp | ontap_select_deploy_administration_utility | - |
redhat | codeready_linux_builder | - |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases