Insecure Handling of Ceph Credentials in libvirt

Insecure Handling of Ceph Credentials in libvirt

CVE-2015-5160 · LOW Severity

AV:L/AC:L/AU:N/C:P/I:N/A:N

libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.

Learn more about our User Device Pen Test.