cbcvebase.
CVE-2015-5160
published 2018-08-20

CVE-2015-5160: libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive…

medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlibvirt< libvirt 2.2.0-1 (bookworm)libvirt 2.2.0-1 (bookworm)
libvirtlibvirt< 2.22.2
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation
redhatlibvirt>= 0 < 2.2.0-12.2.0-1
redhatlibvirt>= 0 < 2.2.0-12.2.0-1
redhatlibvirt>= 0 < 2.2.0-12.2.0-1
redhatlibvirt>= 0 < 2.2.0-12.2.0-1
redhatvirtualization

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM