SPAM: [Security] Arbitrary file reading via malicious VM config

James Brown randomvoidmail at foxmail.com
Wed Nov 27 01:14:28 CET 2024


I suspect a security flaw within ESXi VM import. If a malicious actor forges a VMWare VM config with root paths such as /var/log/auth.log, could lead to potential data leak if the import task is executed.


More information about the pve-devel mailing list