CVE Vulnerabilities

CVE-2022-44020

Improper Preservation of Permissions

Published: Oct 30, 2022 | Modified: Nov 07, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Ubuntu

An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an unsupported, production-like configuration.

Weakness

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Affected Software

Name Vendor Start Version End Version
Sushy-tools Opendev * 0.21.1 (excluding)
Virtualbmc Opendev * 3.0.0 (excluding)
Red Hat OpenStack Platform 13.0 - ELS RedHat python-virtualbmc-0:1.2.0-2.el7ost *
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS RedHat python-virtualbmc-0:1.2.0-2.el7ost *

References