AI Score
Confidence
High
EPSS
Percentile
5.1%
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.
rhn.redhat.com/errata/RHSA-2016-2577.html
www.openwall.com/lists/oss-security/2017/07/21/3
bugs.launchpad.net/ossn/+bug/1686743
bugzilla.redhat.com/show_bug.cgi?id=1245647
wiki.openstack.org/wiki/OSSN/OSSN-0079