Vulnerability Description
An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsupported, production-like configuration."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opendev | Sushy-Tools | < 0.21.1 |
| Opendev | Virtualbmc | < 3.0.0 |
| Fedoraproject | Fedora | 35 |
Related Weaknesses (CWE)
References
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://review.opendev.org/c/openstack/sushy-tools/+/862625PatchVendor Advisory
- https://review.opendev.org/c/openstack/virtualbmc/+/862620PatchVendor Advisory
- https://storyboard.openstack.org/#%21/story/2010382
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://review.opendev.org/c/openstack/sushy-tools/+/862625PatchVendor Advisory
- https://review.opendev.org/c/openstack/virtualbmc/+/862620PatchVendor Advisory
- https://storyboard.openstack.org/#%21/story/2010382
FAQ
What is CVE-2022-44020?
CVE-2022-44020 is a vulnerability with a CVSS score of 5.5 (MEDIUM). An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed li...
How severe is CVE-2022-44020?
CVE-2022-44020 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-44020?
Check the references section above for vendor advisories and patch information. Affected products include: Opendev Sushy-Tools, Opendev Virtualbmc, Fedoraproject Fedora.