Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23428
HistoryApr 10, 2020 - 12:26 a.m.

Information Disclosure

2020-04-1000:26:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.001 Low

EPSS

Percentile

29.5%

xen is vulnerable to information disclosure. A security vulnerability was discovered in the QEMU block format auto-detection, when running fully-virtualized guests. Such fully-virtualized guests, with a raw formatted disk image, were able to write a header to that disk image describing another format. This could allow such guests to read arbitrary files in their hypervisor’s host.