An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an unsupported, production-like configuration.
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sushy-tools | Opendev | * | 0.21.1 (excluding) |
Virtualbmc | Opendev | * | 3.0.0 (excluding) |
Red Hat OpenStack Platform 13.0 - ELS | RedHat | python-virtualbmc-0:1.2.0-2.el7ost | * |
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS | RedHat | python-virtualbmc-0:1.2.0-2.el7ost | * |