Security Advisory

CVE-2020-14301

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-05-27 19:44:34
Last updated 2024-08-04 12:39:36
Assigner redhat
State PUBLISHED

Description

An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.