icon

We found results for “

CVE-2024-31144

Good to know:

icon

Date: March 28, 2024

An issue was discovered in Xapi, where metadata injection attack could be performed against backup/restore functionality. A malicious guest can manipulate its disk to appear to be a metadata backup. To leverage the vulnerability, an attacker would likely need insider information to construct a plausible-looking metadata backup, and would have to persuade a real administrator to perform a data-recovery action. Systems running Xapi v1.249.x are affected.

Language: Python

Severity Score

Severity Score

Top Fix

icon

Upgrade Version

Upgrade to version 54d9b4f4e78c04922d35e60c996b35906a2cadc5

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): HIGH
Privileges Required (PR): HIGH
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

Do you need more information?

Contact Us