CVE-2015-5160Sensitive Information Exposure in Libvirt

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 65.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 20
Latest updateMay 13

Description

libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

Also affects: Enterprise Linux 5, 6.0, 7.3, 7.4, 7.5, 7.6

🔴Vulnerability Details

3
GHSA
GHSA-57w8-4258-hhvg: libvirt before 22022-05-13
OSV
CVE-2015-5160: libvirt before 22018-08-20
CVEList
CVE-2015-5160: libvirt before 22018-08-20

📋Vendor Advisories

2
Red Hat
libvirt: Ceph id/key leaked in the process list2015-08-10
Debian
CVE-2015-5160: libvirt - libvirt before 2.2 includes Ceph credentials on the qemu command line when using...2015

💬Community

1
Bugzilla
CVE-2015-5160 libvirt: Ceph id/key leaked in the process list2015-07-22
CVE-2015-5160 — Sensitive Information Exposure | cvebase