libvirt version 2.3.0 and later is vulnerable to a bad default configuration of verify-peer=no passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libvirt | Redhat | 2.3.0 (including) | 3.9.0 (excluding) |
Libvirt | Ubuntu | artful | * |
Libvirt | Ubuntu | upstream | * |
Libvirt | Ubuntu | zesty | * |