CVE-2020-14301

CWE-2126 documents6 sources
Severity
6.5MEDIUM
EPSS
0.5%
top 34.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 27
Latest updateMay 24

Description

An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDredhat/libvirt6.2.06.3.0
CVEListV5libvirtlibvirt 6.3.0

Also affects: Enterprise Linux 8.0, 8.4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5qrf-45p7-8vrc: An information disclosure vulnerability was found in libvirt in versions before 62022-05-24
CVEList
CVE-2020-14301: An information disclosure vulnerability was found in libvirt in versions before 62021-05-27

📋Vendor Advisories

2
Red Hat
libvirt: leak of sensitive cookie information via dumpxml2020-04-14
Debian
CVE-2020-14301: libvirt - An information disclosure vulnerability was found in libvirt in versions before ...2020

💬Community

1
Bugzilla
CVE-2020-14301 libvirt: leak of sensitive cookie information via dumpxml2020-06-18