Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-44020

Опубликовано: 26 окт. 2022
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsupported, production-like configuration."

A flaw was found in sushy-tools & VirtualBMC, where changing the boot device configuration removes password protection from the managed libvirt XML domain.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8python-sushyNot affected
Red Hat OpenStack Platform 13.0 - ELSpython-virtualbmcFixedRHSA-2022:889608.12.2022
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUSpython-virtualbmcFixedRHSA-2022:889608.12.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-305
https://bugzilla.redhat.com/show_bug.cgi?id=2142678VirtualBMC: removes password protection from the managed libvirt XML domain

EPSS

Процентиль: 27%
0.00094
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
больше 3 лет назад

An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsupported, production-like configuration."

CVSS3: 5.5
github
больше 3 лет назад

OpenStack Sushy-Tools and VirtualBMC Improper Preservation of Permissions

EPSS

Процентиль: 27%
0.00094
Низкий

5.5 Medium

CVSS3