VulnerabilityModified
CVE-2015-5160
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.
MEDIUM 5.5EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- libvirt/libvirt · redhat/virtualization · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2016-2577.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2017/07/21/3Mailing List, Third Party Advisory
- https://bugs.launchpad.net/ossn/+bug/1686743Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1245647Issue Tracking, Third Party Advisory
- https://wiki.openstack.org/wiki/OSSN/OSSN-0079Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2577.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2017/07/21/3Mailing List, Third Party Advisory
- https://bugs.launchpad.net/ossn/+bug/1686743Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1245647Issue Tracking, Third Party Advisory
- https://wiki.openstack.org/wiki/OSSN/OSSN-0079Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.