CVE-2020-14301: Netapp Ontap Select Deploy Administration Utility

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.

Affected products

  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified
  • Red Hat Codeready Linux Builder: affected versions not specified
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Enterprise Linux Eus: version 8.4 only
  • Red Hat Enterprise Linux For IBM Z Systems: version 8.0 only
  • Red Hat Enterprise Linux For IBM Z Systems Eus: version 8.4 only
  • Red Hat Enterprise Linux For Power Little Endian: version 8.0 only
  • Red Hat Enterprise Linux For Power Little Endian Eus: version 8.4 only
  • Red Hat Enterprise Linux Server Aus: version 8.4 only
  • Red Hat Enterprise Linux Server For Power Little Endian Update Services For SAP Solutions: version 8.4 only
  • Red Hat Enterprise Linux Server Update Services For SAP Solutions: version 8.4 only
  • Red Hat Enterprise Linux Tus: version 8.4 only
  • Red Hat Libvirt: from 6.2.0, before 6.3.0 (fixed in 6.3.0)

Published 2021-05-27. Last modified 2026-06-17.