CVE-2014-0028: Red Hat Libvirt
Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.
libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:search_domains restrictions in ACLs and obtain sensitive domain object information via a request to the (1) virConnectDomainEventRegister and (2) virConnectDomainEventRegisterAny functions in the event registration API.
Affected products
- Red Hat Libvirt: version 1.1.1 only; version 1.1.2 only; version 1.1.3 only; version 1.1.4 only; version 1.2.0 only
Published 2014-01-24. Last modified 2026-06-17.