CVE-2020-23793

An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can restart KVMvirtual machine without any authorization. It is not yet known if there will be other other effects.
Configurations

Configuration 1 (hide)

cpe:2.3:a:spice-space:spice-server:0.14.0-6el7_6.1:*:*:*:*:*:*:*

History

21 Nov 2024, 05:14

Type Values Removed Values Added
Summary
  • (es) Se ha descubierto un problema en spice-server spice-server-0.14.0-6.el7_6.1.x86_64 del producto VDI de Redhat. Existe una vulnerabilidad de seguridad que puede reiniciar la máquina virtual KVM sin autorización. Todavía no se sabe si habrá otros efectos.
References () https://github.com/zelat/spice-security-issues - Exploit () https://github.com/zelat/spice-security-issues - Exploit

Information

Published : 2023-08-22 19:16

Updated : 2024-11-21 05:14


NVD link : CVE-2020-23793

Mitre link : CVE-2020-23793

CVE.ORG link : CVE-2020-23793


JSON object : View

Products Affected

spice-space

  • spice-server
CWE
CWE-862

Missing Authorization