Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5pj3-6fqm-8m7m

Опубликовано: 30 окт. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

OpenStack Sushy-Tools and VirtualBMC Improper Preservation of Permissions

An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsupported, production-like configuration."

Пакеты

Наименование

sushy-tools

pip
Затронутые версииВерсия исправления

< 0.21.1

0.21.1

Наименование

virtualbmc

pip
Затронутые версииВерсия исправления

< 3.0.0

3.0.0

EPSS

Процентиль: 27%
0.00094
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-281

Связанные уязвимости

CVSS3: 5.5
redhat
больше 3 лет назад

An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsupported, production-like configuration."

CVSS3: 5.5
nvd
больше 3 лет назад

An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsupported, production-like configuration."

EPSS

Процентиль: 27%
0.00094
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-281