VDB
CVE-2019-13314
CVE-2019-13314
PUBLISHED
CVSS 7.800000190734863 HIGH
virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password option to virt_bootstrap.py.
EPSS 0.05% · 16.6th percentile
Risk Scores
CVSS 3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.05%
16.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | virt-bootstrap | 1.1.0 |
| n/a | n/a | n/a |
Exploit Intelligence
- https://www.redhat.com/archives/virt-tools-list/2019-July/msg00043.html (nist-nvd)
- https://github.com/virt-manager/virt-bootstrap/releases (circl)
- [oss-security] 20190708 CVE-2019-13313, CVE-2019-13314: password disclosure via command line arguments (circl)
- FEDORA-2019-2084f9e721 (circl)
- FEDORA-2019-e465ec0651 (circl)
- openSUSE-SU-2020:1787 (circl)
- openSUSE-SU-2020:1856 (circl)
Timeline
- Jul 5, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://www.redhat.com/archives/virt-tools-list/2019-July/msg00043.html url
- https://github.com/virt-manager/virt-bootstrap/releases url
- [oss-security] 20190708 CVE-2019-13313, CVE-2019-13314: password disclosure via command line arguments mailing-list
- FEDORA-2019-2084f9e721 vendor-advisory
- FEDORA-2019-e465ec0651 vendor-advisory
- openSUSE-SU-2020:1787 vendor-advisory
- openSUSE-SU-2020:1856 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-13314 advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D2PQSLGSTPVQ5WQ4DDKFV4I262JIFXY6 url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YKMQLYAHCDIE5TBXWDNBG7554KWI5QT3 url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2PQSLGSTPVQ5WQ4DDKFV4I262JIFXY6 url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YKMQLYAHCDIE5TBXWDNBG7554KWI5QT3 url