VYPR
Medium severity5.5NVD Advisory· Published Oct 30, 2022· Updated Jun 17, 2026

CVE-2022-44020

CVE-2022-44020

Description

An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsupported, production-like configuration."

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
sushy-toolsPyPI
< 0.21.10.21.1
virtualbmcPyPI
< 3.0.03.0.0

Affected products

8
  • OpenStack/Sushy-Toolsdescription
  • ghsa-coords2 versions
    < 0.21.1+ 1 more
    • (no CPE)range: < 0.21.1
    • (no CPE)range: < 3.0.0
  • cpe:2.3:a:opendev:sushy-tools:*:*:*:*:*:openstack:*:*
    Range: <0.21.1
  • cpe:2.3:a:opendev:virtualbmc:*:*:*:*:*:openstack:*:*
    Range: <3.0.0
  • cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

12

News mentions

0

No linked articles in our index yet.