CVE-2022-44020: Medium severity opendev Sushy-tools Openstack vulnerability
An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsupported, production-like configuration."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/virtualbmcto a version that resolves this vulnerability.Fixed in 3.0.0 - Upgrade
Upgrade
pip/sushy-toolsto a version that resolves this vulnerability.Fixed in 0.21.1
Event History
Frequently Asked Questions
What is the severity of CVE-2022-44020?
CVE-2022-44020 is considered to be of medium severity due to the potential removal of password protection from libvirt XML domains.
How do I fix CVE-2022-44020?
To fix CVE-2022-44020, upgrade to Sushy-Tools version 0.21.1 or VirtualBMC version 3.0.0.
What systems are affected by CVE-2022-44020?
CVE-2022-44020 affects OpenStack Sushy-Tools up to version 0.21.0 and VirtualBMC up to version 2.2.2.
Can I continue using affected versions of software for CVE-2022-44020?
It is not recommended to continue using affected versions, as this could expose your system to security vulnerabilities.
What type of configurations does CVE-2022-44020 impact?
CVE-2022-44020 specifically impacts unsupported, production-like configurations of the affected software.