| Reported on: | 20200420 |
|---|---|
| Published on: | 20200414 |
| Fixed on: | 20200414 |
| Reported by: | Han Han |
|---|---|
| Patched by: | Peter Krempa |
The implementation of cookies for HTTP-based disks formatted them in the XML even if the VIR_DOMAIN_XML_SECURE was not present.
A read-only client can access potentionally sensitive information in the cookies.
Denying access to the readonly libvirt socket will avoid the potential information leak.