Safety vulnerability ID: 51632
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Virtualbmc 3.0.0 includes a fix for CVE-2022-44020: An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain.
NOTE: this only affects an "unsupported, production-like configuration."
Latest version: 3.1.0
Create virtual BMCs for controlling virtual instances via IPMI
An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsupported, production-like configuration." See CVE-2022-44020.
MISC:https://review.opendev.org/c/openstack/sushy-tools/+/862625: https://review.opendev.org/c/openstack/sushy-tools/+/862625
MISC:https://review.opendev.org/c/openstack/virtualbmc/+/862620: https://review.opendev.org/c/openstack/virtualbmc/+/862620
MISC:https://storyboard.openstack.org/#!/story/2010382: https://storyboard.openstack.org/#%21/story/2010382
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application