Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances KVM/QEMU monitoring engine (glances/plugins/vms/engines/virsh.py) passes VM domain names, read directly from virsh list --all output, into f-string command templates that are processed by secure_popen(). secure_popen() is explicitly designed to interpret &&, |, and > as shell operators. Because domain names are never sanitised before interpolation, any user with the ability to create or rename a KVM/QEMU virtual machine can execute arbitrary commands as the OS user running Glances — commonly root on hypervisor hosts. This vulnerability is fixed in 4.5.5.
3.1.5-13.2.3.1+dfsg-13.2.4.2+dfsg-13.4.0.3+dfsg-14.3.0.8+dfsg-14.3.1+dfsg-14.3.1+dfsg-14.3.3+dfsg-12.3-1build12.3-1ubuntu0.1~esm12.10-22.11.1-12.11.1-22.11.1-32.11.1-3ubuntu0.1~esm13.1.0-13.1.1-13.1.3-13.1.3-1ubuntu0.1~esm1Exploitability
AV:LAC:LPR:LUI:NScope
S:UImpact
C:HI:HA:HCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H