Re: [pve-devel] Arbitrary file reading via malicious VM config

2024-11-27 Thread Thomas Lamprecht
Am 27.11.24 um 09:09 schrieb Thomas Lamprecht: > The core assumption is that the admin doing the import fully controls both > sides, > VMWare ESXi and Proxmox VE. > As otherwise this feature makes no sense, if the ESXi isn't trusted, it can > do all > sorts of bad things that just cannot be prote

Re: [pve-devel] Arbitrary file reading via malicious VM config

2024-11-27 Thread Thomas Lamprecht
Hello, First, if you, or anybody else, think they found a problem with security implications then please use our dedicated confidential channels for evaluating that initially: https://pve.proxmox.com/wiki/Security_Reporting If it's a real problem then other users might not be happy about a pub