CVE-2014-7823: Red Hat Libvirt

Medium severity, CVSS 5.0. EPSS: 1.9% chance of exploitation in the next 30 days.

The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.

Affected products

  • Red Hat Libvirt: up to and including 1.2.10; version 1.2.0 only; version 1.2.1 only; version 1.2.2 only; version 1.2.3 only; version 1.2.4 only; …

Published 2014-11-13. Last modified 2026-06-17.