Improper Preservation of Permissions in VirtualBMC - CVE-2022-44020
Published: December 13, 2022 / Updated: March 10, 2023
Vulnerability identifier: #VU70141
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-44020
CWE-ID: CWE-281
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to an error caused by changing boot device configuration, which removes password protection from the managed libvirt XML domain. A local user can gain unauthorized access to sensitive information.
Affected software
VirtualBMC
Sushy-Tools
Fedora
python-virtualbmc (Red Hat package)
python-virtualbmc
Sushy-Tools
Fedora
python-virtualbmc (Red Hat package)
python-virtualbmc
How to mitigate CVE-2022-44020
Install update from vendor's website.
VirtualBMC - update to 3.0.1
Sushy-Tools - update to 0.21.1
python-virtualbmc (Red Hat package) - update to 1.2.0-2.el7ost
python-virtualbmc - addressed in versions 3.0.0-1.fc35, 3.0.0-1.fc36, 3.0.0-1.fc37
Sushy-Tools - update to 0.21.1
python-virtualbmc (Red Hat package) - update to 1.2.0-2.el7ost
python-virtualbmc - addressed in versions 3.0.0-1.fc35, 3.0.0-1.fc36, 3.0.0-1.fc37
External References
- https://storyboard.openstack.org/#!/story/2010382
- https://review.opendev.org/c/openstack/virtualbmc/+/862620
- https://review.opendev.org/c/openstack/sushy-tools/+/862625
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GAD7QJIUWPCKJIGYP7PPHH5DILOEONFE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QMSUGS4B6EBRHBJMTRXL5RIKJTZTEMJC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KEQVJF3OQGSDCSQTQQSC54JEGLMSNB4Q/
- https://bugzilla.redhat.com/show_bug.cgi?id=2142678