2.1 Low
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:L/Au:N/C:P/I:N/A:N
2.3 Low
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
0.0004 Low
EPSS
Percentile
9.8%
An issue was discovered in Xen through 4.14.x. Neither xenstore
implementation does any permission checks when reporting a xenstore watch
event. A guest administrator can watch the root xenstored node, which will
cause notifications for every created, modified, and deleted key. A guest
administrator can also use the special watches, which will cause a
notification every time a domain is created and destroyed. Data may
include: number, type, and domids of other VMs; existence and domids of
driver domains; numbers of virtual interfaces, block devices, vcpus;
existence of virtual framebuffers and their backend style (e.g., existence
of VNC service); Xen VM UUIDs for other domains; timing information about
domain creation and device setup; and some hints at the backend
provisioning of VMs and their devices. The watch events do not contain
values stored in xenstore, only key names. A guest administrator can
observe non-sensitive domain and device lifecycle events relating to other
guests. This information allows some insight into overall system
configuration (including the number and general nature of other guests),
and configuration of other guests (including the number and general nature
of other guests’ devices). This information might be commercially
interesting or might make other attacks easier. There is not believed to be
exposure of sensitive data. Specifically, there is no exposure of VNC
passwords, port numbers, pathnames in host and guest filesystems,
cryptographic keys, or within-guest data.
Author | Note |
---|---|
mdeslaur | hypervisor packages are in universe. For issues in the hypervisor, add appropriate tags to each section, ex: Tags_xen: universe-binary |
2.1 Low
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:L/Au:N/C:P/I:N/A:N
2.3 Low
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
0.0004 Low
EPSS
Percentile
9.8%