OpenStack Sushy-Tools and VirtualBMC Improper Preservation of Permissions
Moderate severity
GitHub Reviewed
Published
Oct 30, 2022
to the GitHub Advisory Database
•
Updated Apr 22, 2024
Description
Published by the National Vulnerability Database
Oct 30, 2022
Published to the GitHub Advisory Database
Oct 30, 2022
Reviewed
Apr 22, 2024
Last updated
Apr 22, 2024
An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsupported, production-like configuration."
References