{"id":"CVE-2019-13314","details":"virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password option to virt_bootstrap.py.","modified":"2026-07-08T19:01:52.991417Z","published":"2019-07-05T14:15:11.547Z","related":["SUSE-SU-2020:3045-1","openSUSE-SU-2020:1787-1","openSUSE-SU-2020:1856-1"],"references":[{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00080.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00026.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D2PQSLGSTPVQ5WQ4DDKFV4I262JIFXY6/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YKMQLYAHCDIE5TBXWDNBG7554KWI5QT3/"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2019/07/08/3"},{"type":"ADVISORY","url":"https://github.com/virt-manager/virt-bootstrap/releases"},{"type":"EVIDENCE","url":"https://www.redhat.com/archives/virt-tools-list/2019-July/msg00043.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/virt-manager/virt-bootstrap","events":[{"introduced":"a88af41bb4b54d7d9adce57a1a1a4118728bef37"},{"last_affected":"a88af41bb4b54d7d9adce57a1a1a4118728bef37"}],"database_specific":{"cpe":"cpe:2.3:a:redhat:virt-bootstrap:1.1.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.1.0"},{"last_affected":"1.1.0"}],"source":"CPE_STRING"}}],"versions":["1.1.0","v1.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13314.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}