#VU94498 Improper neutralization of special elements in output used by a downstream component in Xen - CVE-2024-31144
Published: July 17, 2024
Xen
Xen Project
Description
The vulnerability allows a malicious guest to compromise other guests.
The vulnerability exists due to improper validation of metadata in xapi when restoring data from backup. A malicious guest can manipulate disks to appear to be a metadata backup and trick the guest administrator to recover the system from a malicious backup.
Systems running Xapi v1.249.x are affected.