Vulnerability Details CVE-2019-10183
Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction. This option accepts guest VM password as command line arguments, thus leaking them to others users on the system via process listing. It was introduced recently in the virt-manager v2.2.0 release.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.7%
CVSS Severity
CVSS v3 Score 3.2
CVSS v2 Score 2.1
Products affected by CVE-2019-10183
-
cpe:2.3:a:redhat:virt-manager:2.2.0
-
cpe:2.3:o:redhat:enterprise_linux:8.0