CVE-2020-14301

Publication date

2021-05-27 19:44:34

Family

redhat

State

PUBLISHED

Description

An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.