First published: Tue Apr 14 2020(Updated: )
An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Libvirt | >=6.2.0<6.3.0 | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux Eus | =8.4 | |
Redhat Enterprise Linux For Ibm Z Systems | =8.0 | |
Redhat Enterprise Linux For Ibm Z Systems Eus | =8.4 | |
Redhat Enterprise Linux For Power Little Endian | =8.0 | |
Redhat Enterprise Linux For Power Little Endian Eus | =8.4 | |
Redhat Enterprise Linux Server Aus | =8.4 | |
Redhat Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions | =8.4 | |
Redhat Enterprise Linux Server Update Services For Sap Solutions | =8.4 | |
Redhat Enterprise Linux Tus | =8.4 | |
NetApp ONTAP Select Deploy administration utility | ||
Redhat Codeready Linux Builder | ||
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux Eus | =8.4 | |
Redhat Enterprise Linux For Ibm Z Systems | =8.0 | |
Redhat Enterprise Linux For Ibm Z Systems Eus | =8.4 | |
Redhat Enterprise Linux For Power Little Endian | =8.0 | |
Redhat Enterprise Linux For Power Little Endian Eus | =8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14301 is an information disclosure vulnerability found in libvirt before version 6.3.0.
The severity of CVE-2020-14301 is medium with a CVSS score of 6.5.
CVE-2020-14301 allows a malicious user with a read-only connection to access potentially sensitive information in the domain configuration via HTTP cookies.
To fix CVE-2020-14301, users should update to libvirt version 6.3.0 or later.
You can find more information about CVE-2020-14301 at the following references: [CVE-2020-14301](https://www.cve.org/CVERecord?id=CVE-2020-14301), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-14301), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1848640), [Red Hat Security Advisory](https://access.redhat.com/errata/RHBA-2020:3172).