CVE-2019-10183
published 2019-07-03CVE-2019-10183: Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction. This option…
PriorityP410low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.40%
33.2th percentile
Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction. This option accepts guest VM password as command line arguments, thus leaking them to others users on the system via process listing. It was introduced recently in the virt-manager v2.2.0 release.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | virt-manager | — | — |
| red_hat | virt-install | — | — |
| redhat | enterprise_linux | — | — |
| redhat | virt-manager | — | — |
| redhat | virt-manager | >= 0 < 1:2.2.1-3ubuntu2.1 | 1:2.2.1-3ubuntu2.1 |
| redhat | virt-manager | >= 0 < 1:3.2.0-3 | 1:3.2.0-3 |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv3.3LOW
vendor_debian3.2LOW
vendor_redhat3.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mjgr-85qm-mjv5: Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction
ghsa_unreviewed·2022-05-24
CVE-2019-10183 [LOW] CWE-200 GHSA-mjgr-85qm-mjv5: Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction
Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction. This option accepts guest VM password as command line arguments, thus leaking them to others users on the system via process listing. It was introduced recently in the virt-manager v2.2.0 release.
OSV
CVE-2019-10183: Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction
osv·2019-07-03·CVSS 3.3
CVE-2019-10183 [LOW] CVE-2019-10183: Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction
Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction. This option accepts guest VM password as command line arguments, thus leaking them to others users on the system via process listing. It was introduced recently in the virt-manager v2.2.0 release.
Red Hat
virt-install: unattended option leaks password via command line argument
vendor_redhat·2019-07-02·CVSS 3.2
CVE-2019-10183 [LOW] CWE-200 virt-install: unattended option leaks password via command line argument
virt-install: unattended option leaks password via command line argument
Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction. This option accepts guest VM password as command line arguments, thus leaking them to others users on the system via process listing. It was introduced recently in the virt-manager v2.2.0 release.
The virt-install utility used to provision new virtual machines, in virt-manager v2.2.0, has introduced an option '--unattended' to create VMs without user interaction. This option accepts guest VM password as command line arguments. An attacker could obtain these passwords though process listings on the system.
Package: virt-manager (Red Hat Enterprise Linux 5) - Not affected
Pac
Debian
CVE-2019-10183: virt-manager - Virt-install(1) utility used to provision new virtual machines has introduced an...
vendor_debian·2019·CVSS 3.2
CVE-2019-10183 [LOW] CVE-2019-10183: virt-manager - Virt-install(1) utility used to provision new virtual machines has introduced an...
Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction. This option accepts guest VM password as command line arguments, thus leaking them to others users on the system via process listing. It was introduced recently in the virt-manager v2.2.0 release.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10183 virt-manager: virt-install: unattended option leaks password via command line argument [fedora-all]
bugzilla·2019-07-03·CVSS 3.2
CVE-2019-10183 [LOW] CVE-2019-10183 virt-manager: virt-install: unattended option leaks password via command line argument [fedora-all]
CVE-2019-10183 virt-manager: virt-install: unattended option leaks password via command line argument [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2019-10183 virt-install: unattended option leaks password via command line argument
bugzilla·2019-07-02·CVSS 3.2
CVE-2019-10183 [LOW] CVE-2019-10183 virt-install: unattended option leaks password via command line argument
CVE-2019-10183 virt-install: unattended option leaks password via command line argument
Virt-install(1) utility used to provision new virtual machines has introduced an option
'--unattended' to create VMs without user interaction. This option accepts guest VM
password as command line arguments. Thus leaking them to others users on the system
via process listing. It was introduced recently in the virt-manager v2.2.0 release.
Upstream patch:
-> https://www.redhat.com/archives/virt-tools-list/2019-July/msg00014.html
Reference:
-> https://virt-manager.org/download/
-> https://www.openwall.com/lists/oss-security/2019/07/03/1
Discussion:
Acknowledgments:
Name: Daniel P. Berrangé (Red Hat Inc.)
---
Created virt-manager tracking bugs for this issue:
Affects: fedora-all [bug 1726536]
---
2019-07-03
Published