First published: Fri Jul 05 2019(Updated: )
virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password option to virt_bootstrap.py.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Virt-bootstrap | =1.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13314 has a medium severity rating due to the potential exposure of sensitive root password information.
To fix CVE-2019-13314, upgrade virt-bootstrap to a version higher than 1.1.0.
The vulnerability in CVE-2019-13314 allows local users to potentially discover a root password via process listing.
CVE-2019-13314 specifically affects users of virt-bootstrap version 1.1.0.
CVE-2019-13314 cannot be exploited remotely as it requires local user access to the system.