Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12199
HistoryJan 15, 2019 - 9:13 a.m.

Information Disclosure

2019-01-1509:13:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

EPSS

0

Percentile

5.1%

libvirt is vulnerable to information disclosure attacks. The vulnerability exists as libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.

References